GroupAttribution unconfirmed; compromised Malaysian company's Google Ads account used as delivery infrastructure proxyTypeMalvertising / ClickFix Infostealer Campaign — cross-platform macOS and WindowsMalwareMacSync — macOS Malware as a Service infostealer targeting browser credentials, Keychain databases, session cookies, and cryptocurrency wallets; Trojan.Stealer.GJ / Trojan.Stealer.GK — Windows credential stealers delivered via mshta.