Researchers are tracking a fast-spreading malware campaign that uses malicious search engine advertisements to deliver trojanized installers for popular free software.

Victims searching for well-known tools are shown convincing lookalike ads leading to cloned download sites. The installers deliver the legitimate application alongside an information stealer signed with stolen code-signing certificates to evade security warnings.

The stealer harvests browser passwords, session cookies, cryptocurrency wallets and messaging tokens, feeding an underground economy in compromised accounts.

Ad networks say they are removing the malicious campaigns, but researchers note the operators rotate advertiser identities within hours. Users are advised to download software only from official vendor domains.