#atomicstealer — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #atomicstealer, aggregated by home.social.
-
MacOS ClickFix Attack Exploits Script Editor to Evade Apple Warnings
The cat-and-mouse game continues: after Apple added security warnings to Terminal, attackers behind the Atomic Stealer family adapted their ClickFix attack to exploit Script Editor instead. This latest move shows how adversaries constantly evolve to evade detection.
#Macos #ClickfixAttack #AtomicStealer #MalwareOperations #EmergingThreats
-
ah ben voilà, je me disais : quand est-ce que le bon vieux AppleScript allait être intégré dans les campagnes ClickFix visant macOS ?
Il aura fallu qu’Apple introduise sa nouvelle fonctionnalité de protection du copier/coller dans le Terminal
( d'ailleurs et comme d'hab 😁 « largement inspirée », par le travail de Patrick Wardle dans blockblock :
https://objective-see.org/blog/blog_0x87.html )…pour que la campagne Atomic Stealer passe à Script Editor.
⬇️
ClickFix technique uses Script Editor instead of Terminal on macOS
Jamf Threat Labs discovered a ClickFix-style macOS attack that abuses the applescript:// URL scheme to launch Script Editor and deliver an Atomic Stealer infostealer payload — bypassing Terminal entirely.
👇
https://www.jamf.com/blog/clickfix-macos-script-editor-atomic-stealer/ -
Forschende von Jamf Threat berichten heute über eine neue Variante einer bekannten Cyberangriffsmethode. Der Angriff zielt auf Mac-Nutzende ab und nutzt eine ziemlich geschickte Täuschung, um Schadsoftware auf den Mac zu schleusen.
Mehr: https://digiprax.maniabel.work/archiv/1248
#infostealer #AtomicStealer #jamf #infosec #up2date #macOS #ScriptEditor #ClickFix
-
macOS Users Targeted in ClickFix Malware Campaign
macOS users are being targeted in a sneaky new malware campaign called ClickFix, which tricks them into executing malicious commands by abusing the Script Editor and Terminal tools. This latest attack raises a pressing question: how can we trust our trusted tools when they're being exploited by hackers?
#Macos #AtomicStealer #Clickfix #MalwareOperations #EmergingThreats
-
Malicious OpenClaw Skills Used to Distribute Atomic MacOS Stealer
#OpenClaw #AtomicStealer
https://www.trendmicro.com/en_us/research/26/b/openclaw-skills-used-to-distribute-atomic-macos-stealer.html -
Malicious OpenClaw Skills Used to Distribute Atomic MacOS Stealer
#OpenClaw #AtomicStealer
https://www.trendmicro.com/en_us/research/26/b/openclaw-skills-used-to-distribute-atomic-macos-stealer.html -
Infostealers without borders: macOS, Python stealers, and platform abuse
#DigitStealer #MacSyncStealer #AtomicStealer #PXAStealer
https://www.microsoft.com/en-us/security/blog/2026/02/02/infostealers-without-borders-macos-python-stealers-and-platform-abuse/ -
Infostealers without borders: macOS, Python stealers, and platform abuse
#DigitStealer #MacSyncStealer #AtomicStealer #PXAStealer
https://www.microsoft.com/en-us/security/blog/2026/02/02/infostealers-without-borders-macos-python-stealers-and-platform-abuse/ -
🚨 Fake Malwarebytes, LastPass & 70+ brands abused on GitHub to spread Atomic Stealer (AMOS).
🔹 Fake repos + SEO + sponsored ads = malware installs
🔹 Copy-paste terminal commands (curl … | bash) deliver the payload instantly
🔹 Brands targeted include password managers, fintech apps, and dev tools
⚠️ Another reminder: only trust official developer sites.
💬 Do you think GitHub & Google should be held more accountable for catching these campaigns earlier?Follow @technadu for #CyberSecurity insights.
#Malware #AtomicStealer #AMOS #Infostealer #MacOS #Malwarebytes #LastPass #GitHubSecurity
-
Fake Malwarebytes, LastPass, and others on GitHub serve malware https://www.malwarebytes.com/blog/news/2025/09/fake-malwarebytes-lastpass-and-others-on-github-serve-malware #informationstealer #MalwarebytesforMac #Atomicstealer #Threats #GitHub #News #amos
-
Fake Malwarebytes, LastPass, and others on GitHub serve malware https://www.malwarebytes.com/blog/news/2025/09/fake-malwarebytes-lastpass-and-others-on-github-serve-malware #informationstealer #MalwarebytesforMac #Atomicstealer #Threats #GitHub #News #amos
-
🚨 macOS users are being hit with a widespread infostealer campaign.
LastPass warns that hackers are using fake GitHub repos + SEO tricks to deliver the Atomic Stealer (AMOS) malware.⚠️ Impersonated brands: password managers, banks, crypto wallets, AI tools
⚠️ Ongoing since July, with multiple fake repos removed
⚠️ Trust in GitHub & Google Ads is being weaponized
💬 How do you think platforms can balance openness with stronger malware detection?
🔔 Follow @technadu for daily cyber threat updates.#macOS #Infostealer #AtomicStealer #AMOS #GitHubThreats #LastPass #Cybercrime #CyberResilience #TechNadu
-
Atomic macOS Stealer now includes a backdoor for persistent access
#AtomicStealer
https://moonlock.com/amos-backdoor-persistent-access -
Atomic macOS Stealer now includes a backdoor for persistent access
#AtomicStealer
https://moonlock.com/amos-backdoor-persistent-access -
Macs targeted by info stealers in new era of cyberthreats https://www.malwarebytes.com/blog/apple/2025/02/macs-targeted-by-info-stealers-in-new-era-of-cyberthreats #Atomicstealer #infostealers #poseidon #Apple #amos
-
Macs targeted by info stealers in new era of cyberthreats https://www.malwarebytes.com/blog/apple/2025/02/macs-targeted-by-info-stealers-in-new-era-of-cyberthreats #Atomicstealer #infostealers #poseidon #Apple #amos
-
📬 Lumma Stealer statt KI-App: Malware befällt Windows und macOS
#ITSicherheit #Malware #AMOS #AtomicStealer #EditProAI #KIAnwendungen #KIApps #LummaStealer https://sc.tarnkappe.info/ce0d41 -
📬 Lumma Stealer statt KI-App: Malware befällt Windows und macOS
#ITSicherheit #Malware #AMOS #AtomicStealer #EditProAI #KIAnwendungen #KIApps #LummaStealer https://sc.tarnkappe.info/ce0d41 -
Apple picking: Bobbing for Atomic Stealer & other macOS malware
#AtomicStealer
https://redcanary.com/blog/threat-detection/atomic-stealer/ -
A week in security (September 2 – September 8) https://www.malwarebytes.com/blog/news/2024/09/a-week-in-security-september-2-september-8 #PlannedParenthood #Atomicstealer #hellopervert #lowes #News
-
Malvertising Campaign Lures Mac Users with Fake Microsoft Teams Ad https://thecyberexpress.com/malvertising-campaign-lures-macos-users-teams/ #TheCyberExpressNews #CybersecurityNews #TheCyberExpress #MicrosoftTeams #FirewallDaily #AtomicStealer #Poseidon #malware #macOS
-
Malvertising Campaign Lures Mac Users with Fake Microsoft Teams Ad https://thecyberexpress.com/malvertising-campaign-lures-macos-users-teams/ #TheCyberExpressNews #CybersecurityNews #TheCyberExpress #MicrosoftTeams #FirewallDaily #AtomicStealer #Poseidon #malware #macOS
-
Fake Microsoft Teams for Mac delivers Atomic Stealer https://www.malwarebytes.com/blog/threat-intelligence/2024/07/fake-microsoft-teams-for-mac-delivers-atomic-stealer #ThreatIntelligence #MicrosoftTeams #Atomicstealer #malvertising #Apple #mac
-
Fake Microsoft Teams for Mac delivers Atomic Stealer https://www.malwarebytes.com/blog/threat-intelligence/2024/07/fake-microsoft-teams-for-mac-delivers-atomic-stealer #ThreatIntelligence #MicrosoftTeams #Atomicstealer #malvertising #Apple #mac
-
‘Poseidon’ Mac stealer distributed via Google ads https://www.malwarebytes.com/blog/cybercrime/2024/06/poseidon-mac-stealer-distributed-via-google-ads #ThreatIntelligence #Atomicstealer #Cybercrime #poseidon #mac
-
‘Poseidon’ Mac stealer distributed via Google ads https://www.malwarebytes.com/blog/cybercrime/2024/06/poseidon-mac-stealer-distributed-via-google-ads #ThreatIntelligence #Atomicstealer #Cybercrime #poseidon #mac
-
Malicious ad for Arc browser -> #AtomicStealer
arcthost[.]org
arc-download[.]com
zestyahhdog[.]com/Arc12645413[.]dmgC2: 79.137.192[.]4/p2p
-
Malicious ad for Arc browser -> #AtomicStealer
arcthost[.]org
arc-download[.]com
zestyahhdog[.]com/Arc12645413[.]dmgC2: 79.137.192[.]4/p2p
-
🚨 Malicious Zoom ad for Mac & Windows 🚨
Google ad ➡️ Fake Zoom site ➡️ Payload🔑
🤓 Fake advertiser: Jessica Babcok
⚠️ Zoom site: zocmstranslate[.]com🔹Mac (#atomicstealer, C2: 5.182.86[.]95)
🔹Windows (#LummaStealer, C2: stiffraspyofkwsl[.]shop) -
🚨 Malicious Zoom ad for Mac & Windows 🚨
Google ad ➡️ Fake Zoom site ➡️ Payload🔑
🤓 Fake advertiser: Jessica Babcok
⚠️ Zoom site: zocmstranslate[.]com🔹Mac (#atomicstealer, C2: 5.182.86[.]95)
🔹Windows (#LummaStealer, C2: stiffraspyofkwsl[.]shop) -
Jamf warns of two ongoing infostealer campaigns target macOS environments: Atomic Stealer being spread through Sponsored Ads (malvertising) and the attempted execution of an unsigned executable with a bad hash from Meethub. "Many of these stealers are targeting individuals involved in the crypto industry with a focus on harvesting credentials along with data from various crypto wallets." Attack chains described, IOC provided. 🔗 https://www.jamf.com/blog/infostealers-pose-threat-to-macos/
-
Jamf warns of two ongoing infostealer campaigns target macOS environments: Atomic Stealer being spread through Sponsored Ads (malvertising) and the attempted execution of an unsigned executable with a bad hash from Meethub. "Many of these stealers are targeting individuals involved in the crypto industry with a focus on harvesting credentials along with data from various crypto wallets." Attack chains described, IOC provided. 🔗 https://www.jamf.com/blog/infostealers-pose-threat-to-macos/
-
📬 Infostealer-Angriffe auf macOS-User nehmen drastisch zu
#ITSicherheit #Malware #ArcBrowser #AtomicStealer #Infostealer #macOS #Malwaretising #meethub #Realst https://sc.tarnkappe.info/5c5a58 -
📬 Infostealer-Angriffe auf macOS-User nehmen drastisch zu
#ITSicherheit #Malware #ArcBrowser #AtomicStealer #Infostealer #macOS #Malwaretising #meethub #Realst https://sc.tarnkappe.info/5c5a58 -
Dark Web Actor Selling Source Code for Rust-Based Information Stealer https://thecyberexpress.com/source-code-sale-of-new-information-stealer/ #informationstealers #InformationStealer #TheCyberExpress #FirewallDaily #AtomicStealer #AsukaStealer #DarkWebNews #InfoStealer #Crackingx
-
Atomic Stealer rings in the new year with updated version
https://www.malwarebytes.com/blog/threat-intelligence/2024/01/atomic-stealer-rings-in-the-new-year-with-updated-version -
Atomic Stealer rings in the new year with updated version
https://www.malwarebytes.com/blog/threat-intelligence/2024/01/atomic-stealer-rings-in-the-new-year-with-updated-version -
It’s not all rosy in the land of macOS, as a new malware variant has been discovered that explicitly targets Apple users. Luckily, there are things you can do to protect yourself.
#apple #macos #malware #atomicstealer
https://tchlp.com/46CY9GC -
It’s not all rosy in the land of macOS, as a new malware variant has been discovered that explicitly targets Apple users. Luckily, there are things you can do to protect yourself.
#apple #macos #malware #atomicstealer
https://tchlp.com/46CY9GC -
La campaña ClearFake implementa #malware #AtomicStealer para macOS
#ciberseguridad #CyberSecurity #macOS
https://mecambioamac.com/la-campana-clearfake-implementa-malware-atomic-stealer-para-macos/
-
Atomic Stealer, also referred to as AMOS, was initially documented in April 2023.
#Cybersecurity #Apple #Malware #ClearFake #AtomicStealer #macOs
-
Atomic Stealer, also referred to as AMOS, was initially documented in April 2023.
#Cybersecurity #Apple #Malware #ClearFake #AtomicStealer #macOs
-
Only 10 days into October and still lots of new #macOS #apple #AtomicStealer variants all over VT.
57 and counting...
Want to play? See the updated #malware IOCs for October here:
https:/s1.ai/amos -
Only 10 days into October and still lots of new #macOS #apple #AtomicStealer variants all over VT.
57 and counting...
Want to play? See the updated #malware IOCs for October here:
https:/s1.ai/amos -
KrebsonSecurity: ‘Snatch’ Ransom Group Exposes Visitor IP Addresses https://krebsonsecurity.com/2023/09/snatch-ransom-group-exposes-visitor-ip-addresses/ #TrustwaveSpiderlabs #Ne'er-Do-WellNews #MihailKolesnikov #8BaseRansomware #DomainTools.com #MicrosoftTeams #AtomicStealer #DataBreaches #Malwarebytes #Breadcrumbs #Ransomware #Google.com #@htmalgae #Rilide
-
KrebsonSecurity: ‘Snatch’ Ransom Group Exposes Visitor IP Addresses https://krebsonsecurity.com/2023/09/snatch-ransom-group-exposes-visitor-ip-addresses/ #TrustwaveSpiderlabs #Ne'er-Do-WellNews #MihailKolesnikov #8BaseRansomware #DomainTools.com #MicrosoftTeams #AtomicStealer #DataBreaches #Malwarebytes #Breadcrumbs #Ransomware #Google.com #@htmalgae #Rilide
-
KrebsonSecurity: ‘Snatch’ Ransom Group Exposes Visitor IP Addresses https://krebsonsecurity.com/2023/09/snatch-ransom-group-exposes-visitor-ip-addresses/ #TrustwaveSpiderlabs #Ne'er-Do-WellNews #MihailKolesnikov #8BaseRansomware #DomainTools.com #MicrosoftTeams #AtomicStealer #DataBreaches #Malwarebytes #Breadcrumbs #Ransomware #Google.com #@htmalgae #Rilide
-
KrebsonSecurity: ‘Snatch’ Ransom Group Exposes Visitor IP Addresses https://krebsonsecurity.com/2023/09/snatch-ransom-group-exposes-visitor-ip-addresses/ #TrustwaveSpiderlabs #Ne'er-Do-WellNews #MihailKolesnikov #8BaseRansomware #DomainTools.com #MicrosoftTeams #AtomicStealer #DataBreaches #Malwarebytes #Breadcrumbs #Ransomware #Google.com #@htmalgae #Rilide
-
KrebsonSecurity: ‘Snatch’ Ransom Group Exposes Visitor IP Addresses https://krebsonsecurity.com/2023/09/snatch-ransom-group-exposes-visitor-ip-addresses/ #TrustwaveSpiderlabs #Ne'er-Do-WellNews #MihailKolesnikov #8BaseRansomware #DomainTools.com #MicrosoftTeams #AtomicStealer #DataBreaches #Malwarebytes #Breadcrumbs #Ransomware #Google.com #@htmalgae #Rilide
-
KrebsonSecurity: ‘Snatch’ Ransom Group Exposes Visitor IP Addresses https://krebsonsecurity.com/2023/09/snatch-ransom-group-exposes-visitor-ip-addresses/ #TrustwaveSpiderlabs #Ne'er-Do-WellNews #MihailKolesnikov #8BaseRansomware #DomainTools.com #MicrosoftTeams #AtomicStealer #DataBreaches #Malwarebytes #Breadcrumbs #Ransomware #Google.com #@htmalgae #Rilide