Hackers Turn X Promoted Posts into a Mac Malware Delivery Network Through Sponsored Ads

A new malware campaign is spreading through sponsored advertisements on X, targeting macOS users with trojanized software downloads.

AppleThreat Staff
1 Min Read

Security researchers have identified a new malware campaign spreading through sponsored advertisements on X (formerly Twitter), targeting macOS users with information-stealing payloads delivered via malvertising.

How Hijacked Ads Slip Past Platform Defenses

According to 9to5Mac, the malware is distributed through promoted posts on X that impersonate legitimate software and services. When users click on these sponsored advertisements, they are redirected to malicious websites that serve trojanized applications disguised as popular Mac software.

From Click to Full Compromise in Seconds

The malware delivered through this campaign is designed to steal sensitive information from infected Macs, including browser credentials, cryptocurrency wallet data, and other personal information. The trojanized applications mimic legitimate software such as Adobe Creative Cloud and Slack.

How to Lock Down Your Mac Against Sponsored Threats

Mac users are advised to exercise caution when clicking on promoted posts on X. Enabling Gatekeeper, running up-to-date security software, and avoiding downloads from third-party sources provides strong protection. Apple’s XProtect technology should detect known variants.

Share This Article