home.social

#atomicstealer — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #atomicstealer, aggregated by home.social.

fetched live
  1. ClickFix Campaign Targets macOS Users with Atomic Stealer Malware

    A macOS ClickFix campaign spanning over 250 domains now uses browser fingerprinting to hide its fake "Download for macOS" lure from crawlers and researchers, while still serving it to genuine Mac users who are tricked into running a Terminal command that deploys the AMOS infostealer.

    Pulse ID: 6a74853991cc8881d222ead0
    Pulse Link: otx.alienvault.com/pulse/6a748
    Pulse Author: cryptocti
    Created: 2026-08-06 12:59:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AMOS #Atomic #AtomicStealer #Browser #CyberSecurity #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #bot #cryptocti

  2. From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

    Microsoft Threat Intelligence identified a macOS ClickFix operation distributing infostealers including MacSync and Atomic Stealer through over 250 algorithmically generated domains. The campaign evolved from openly displaying malicious content to implementing server-side browser fingerprinting that only reveals lures to visitors whose environment matches genuine macOS browsers. The fingerprinting gate collects browser attributes, hardware details via WebGL, and environmental characteristics to filter out crawlers and sandboxes. Victims are shown fake download pages with Terminal commands that retrieve remote scripts, ultimately deploying AMOS infostealer to harvest credentials, browser data, cryptocurrency wallets, and authentication stores. This Traffic Distribution System approach significantly reduces visibility for security researchers and automated analysis tools while maintaining access to intended targets. The operation represents a notable shift in tradecraft, adding sophisticated cloaking to exis...

    Pulse ID: 6a73869b069fb3586fddadf9
    Pulse Link: otx.alienvault.com/pulse/6a738
    Pulse Author: AlienVault
    Created: 2026-08-05 18:53:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AMOS #Atomic #AtomicStealer #Browser #CyberSecurity #ICS #InfoSec #InfoStealer #Mac #MacOS #Microsoft #OTX #OpenThreatExchange #RAT #bot #cryptocurrency #AlienVault

  3. 250+ macOS ClickFix Domains Use Browser Fingerprinting to Hide Atomic Stealer Attacks

    Indicators extracted from public reporting. Source: cybersecuritynews.com/158536-2

    Pulse ID: 6a7421ea3cb7d6ca6a2de878
    Pulse Link: otx.alienvault.com/pulse/6a742
    Pulse Author: CyberHunter_NL
    Created: 2026-08-06 05:55:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Atomic #AtomicStealer #Browser #CyberSecurity #HTTP #HTTPS #InfoSec #Mac #MacOS #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  4. ah ben voilà, je me disais : quand est-ce que le bon vieux AppleScript allait être intégré dans les campagnes ClickFix visant macOS ?

    Il aura fallu qu’Apple introduise sa nouvelle fonctionnalité de protection du copier/coller dans le Terminal
    ( d'ailleurs et comme d'hab 😁 « largement inspirée », par le travail de Patrick Wardle dans blockblock :
    objective-see.org/blog/blog_0x )

    …pour que la campagne Atomic Stealer passe à Script Editor.
    ⬇️
    ClickFix technique uses Script Editor instead of Terminal on macOS
    Jamf Threat Labs discovered a ClickFix-style macOS attack that abuses the applescript:// URL scheme to launch Script Editor and deliver an Atomic Stealer infostealer payload — bypassing Terminal entirely.
    👇
    jamf.com/blog/clickfix-macos-s

    #cyberveille #macos #atomicstealer

  5. Forschende von Jamf Threat berichten heute über eine neue Variante einer bekannten Cyberangriffsmethode. Der Angriff zielt auf Mac-Nutzende ab und nutzt eine ziemlich geschickte Täuschung, um Schadsoftware auf den Mac zu schleusen.

    Mehr: digiprax.maniabel.work/archiv/

    #infostealer #AtomicStealer #jamf #infosec #up2date #macOS #ScriptEditor #ClickFix

  6. Malicious ad for Arc browser -> #AtomicStealer

    arcthost[.]org
    arc-download[.]com
    zestyahhdog[.]com/Arc12645413[.]dmg

    C2: 79.137.192[.]4/p2p

    #malvertising #threatintel

  7. 🚨 Malicious Zoom ad for Mac & Windows 🚨

    Google ad ➡️ Fake Zoom site ➡️ Payload🔑

    🤓 Fake advertiser: Jessica Babcok
    ⚠️ Zoom site: zocmstranslate[.]com

    🔹Mac (#atomicstealer, C2: 5.182.86[.]95)
    🔹Windows (#LummaStealer, C2: stiffraspyofkwsl[.]shop)

    #malvertising #threatintel

  8. Jamf warns of two ongoing infostealer campaigns target macOS environments: Atomic Stealer being spread through Sponsored Ads (malvertising) and the attempted execution of an unsigned executable with a bad hash from Meethub. "Many of these stealers are targeting individuals involved in the crypto industry with a focus on harvesting credentials along with data from various crypto wallets." Attack chains described, IOC provided. 🔗 jamf.com/blog/infostealers-pos

    #infostealer #threatintel #IOC #AtomicStealer #Meethub

  9. It’s not all rosy in the land of macOS, as a new malware variant has been discovered that explicitly targets Apple users. Luckily, there are things you can do to protect yourself.

    #apple #macos #malware #atomicstealer
    tchlp.com/46CY9GC

  10. Only 10 days into October and still lots of new #macOS #apple #AtomicStealer variants all over VT.
    57 and counting...
    Want to play? See the updated #malware IOCs for October here:
    https:/s1.ai/amos