#atomicstealer — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #atomicstealer, aggregated by home.social.
-
ClickFix Campaign Targets macOS Users with Atomic Stealer Malware
A macOS ClickFix campaign spanning over 250 domains now uses browser fingerprinting to hide its fake "Download for macOS" lure from crawlers and researchers, while still serving it to genuine Mac users who are tricked into running a Terminal command that deploys the AMOS infostealer.
Pulse ID: 6a74853991cc8881d222ead0
Pulse Link: https://otx.alienvault.com/pulse/6a74853991cc8881d222ead0
Pulse Author: cryptocti
Created: 2026-08-06 12:59:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AMOS #Atomic #AtomicStealer #Browser #CyberSecurity #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #bot #cryptocti
-
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
Microsoft Threat Intelligence identified a macOS ClickFix operation distributing infostealers including MacSync and Atomic Stealer through over 250 algorithmically generated domains. The campaign evolved from openly displaying malicious content to implementing server-side browser fingerprinting that only reveals lures to visitors whose environment matches genuine macOS browsers. The fingerprinting gate collects browser attributes, hardware details via WebGL, and environmental characteristics to filter out crawlers and sandboxes. Victims are shown fake download pages with Terminal commands that retrieve remote scripts, ultimately deploying AMOS infostealer to harvest credentials, browser data, cryptocurrency wallets, and authentication stores. This Traffic Distribution System approach significantly reduces visibility for security researchers and automated analysis tools while maintaining access to intended targets. The operation represents a notable shift in tradecraft, adding sophisticated cloaking to exis...
Pulse ID: 6a73869b069fb3586fddadf9
Pulse Link: https://otx.alienvault.com/pulse/6a73869b069fb3586fddadf9
Pulse Author: AlienVault
Created: 2026-08-05 18:53:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AMOS #Atomic #AtomicStealer #Browser #CyberSecurity #ICS #InfoSec #InfoStealer #Mac #MacOS #Microsoft #OTX #OpenThreatExchange #RAT #bot #cryptocurrency #AlienVault
-
250+ macOS ClickFix Domains Use Browser Fingerprinting to Hide Atomic Stealer Attacks
Indicators extracted from public reporting. Source: https://cybersecuritynews.com/158536-2250-macos-clickfix-domains/
Pulse ID: 6a7421ea3cb7d6ca6a2de878
Pulse Link: https://otx.alienvault.com/pulse/6a7421ea3cb7d6ca6a2de878
Pulse Author: CyberHunter_NL
Created: 2026-08-06 05:55:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Atomic #AtomicStealer #Browser #CyberSecurity #HTTP #HTTPS #InfoSec #Mac #MacOS #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
ah ben voilà, je me disais : quand est-ce que le bon vieux AppleScript allait être intégré dans les campagnes ClickFix visant macOS ?
Il aura fallu qu’Apple introduise sa nouvelle fonctionnalité de protection du copier/coller dans le Terminal
( d'ailleurs et comme d'hab 😁 « largement inspirée », par le travail de Patrick Wardle dans blockblock :
https://objective-see.org/blog/blog_0x87.html )…pour que la campagne Atomic Stealer passe à Script Editor.
⬇️
ClickFix technique uses Script Editor instead of Terminal on macOS
Jamf Threat Labs discovered a ClickFix-style macOS attack that abuses the applescript:// URL scheme to launch Script Editor and deliver an Atomic Stealer infostealer payload — bypassing Terminal entirely.
👇
https://www.jamf.com/blog/clickfix-macos-script-editor-atomic-stealer/ -
Forschende von Jamf Threat berichten heute über eine neue Variante einer bekannten Cyberangriffsmethode. Der Angriff zielt auf Mac-Nutzende ab und nutzt eine ziemlich geschickte Täuschung, um Schadsoftware auf den Mac zu schleusen.
Mehr: https://digiprax.maniabel.work/archiv/1248
#infostealer #AtomicStealer #jamf #infosec #up2date #macOS #ScriptEditor #ClickFix
-
Malicious OpenClaw Skills Used to Distribute Atomic MacOS Stealer
#OpenClaw #AtomicStealer
https://www.trendmicro.com/en_us/research/26/b/openclaw-skills-used-to-distribute-atomic-macos-stealer.html -
Infostealers without borders: macOS, Python stealers, and platform abuse
#DigitStealer #MacSyncStealer #AtomicStealer #PXAStealer
https://www.microsoft.com/en-us/security/blog/2026/02/02/infostealers-without-borders-macos-python-stealers-and-platform-abuse/ -
Fake Malwarebytes, LastPass, and others on GitHub serve malware https://www.malwarebytes.com/blog/news/2025/09/fake-malwarebytes-lastpass-and-others-on-github-serve-malware #informationstealer #MalwarebytesforMac #Atomicstealer #Threats #GitHub #News #amos
-
Atomic macOS Stealer now includes a backdoor for persistent access
#AtomicStealer
https://moonlock.com/amos-backdoor-persistent-access -
Macs targeted by info stealers in new era of cyberthreats https://www.malwarebytes.com/blog/apple/2025/02/macs-targeted-by-info-stealers-in-new-era-of-cyberthreats #Atomicstealer #infostealers #poseidon #Apple #amos
-
📬 Lumma Stealer statt KI-App: Malware befällt Windows und macOS
#ITSicherheit #Malware #AMOS #AtomicStealer #EditProAI #KIAnwendungen #KIApps #LummaStealer https://sc.tarnkappe.info/ce0d41 -
Malvertising Campaign Lures Mac Users with Fake Microsoft Teams Ad https://thecyberexpress.com/malvertising-campaign-lures-macos-users-teams/ #TheCyberExpressNews #CybersecurityNews #TheCyberExpress #MicrosoftTeams #FirewallDaily #AtomicStealer #Poseidon #malware #macOS
-
Fake Microsoft Teams for Mac delivers Atomic Stealer https://www.malwarebytes.com/blog/threat-intelligence/2024/07/fake-microsoft-teams-for-mac-delivers-atomic-stealer #ThreatIntelligence #MicrosoftTeams #Atomicstealer #malvertising #Apple #mac
-
‘Poseidon’ Mac stealer distributed via Google ads https://www.malwarebytes.com/blog/cybercrime/2024/06/poseidon-mac-stealer-distributed-via-google-ads #ThreatIntelligence #Atomicstealer #Cybercrime #poseidon #mac
-
Malicious ad for Arc browser -> #AtomicStealer
arcthost[.]org
arc-download[.]com
zestyahhdog[.]com/Arc12645413[.]dmgC2: 79.137.192[.]4/p2p
-
🚨 Malicious Zoom ad for Mac & Windows 🚨
Google ad ➡️ Fake Zoom site ➡️ Payload🔑
🤓 Fake advertiser: Jessica Babcok
⚠️ Zoom site: zocmstranslate[.]com🔹Mac (#atomicstealer, C2: 5.182.86[.]95)
🔹Windows (#LummaStealer, C2: stiffraspyofkwsl[.]shop) -
Jamf warns of two ongoing infostealer campaigns target macOS environments: Atomic Stealer being spread through Sponsored Ads (malvertising) and the attempted execution of an unsigned executable with a bad hash from Meethub. "Many of these stealers are targeting individuals involved in the crypto industry with a focus on harvesting credentials along with data from various crypto wallets." Attack chains described, IOC provided. 🔗 https://www.jamf.com/blog/infostealers-pose-threat-to-macos/
-
📬 Infostealer-Angriffe auf macOS-User nehmen drastisch zu
#ITSicherheit #Malware #ArcBrowser #AtomicStealer #Infostealer #macOS #Malwaretising #meethub #Realst https://sc.tarnkappe.info/5c5a58 -
Atomic Stealer rings in the new year with updated version
https://www.malwarebytes.com/blog/threat-intelligence/2024/01/atomic-stealer-rings-in-the-new-year-with-updated-version -
It’s not all rosy in the land of macOS, as a new malware variant has been discovered that explicitly targets Apple users. Luckily, there are things you can do to protect yourself.
#apple #macos #malware #atomicstealer
https://tchlp.com/46CY9GC -
Atomic Stealer, also referred to as AMOS, was initially documented in April 2023.
#Cybersecurity #Apple #Malware #ClearFake #AtomicStealer #macOs
-
Only 10 days into October and still lots of new #macOS #apple #AtomicStealer variants all over VT.
57 and counting...
Want to play? See the updated #malware IOCs for October here:
https:/s1.ai/amos -
‘Snatch’ Ransom Group Exposes Visitor IP Addresses https://krebsonsecurity.com/2023/09/snatch-ransom-group-exposes-visitor-ip-addresses/ #TrustwaveSpiderlabs #Ne'er-Do-WellNews #MihailKolesnikov #8BaseRansomware #DomainTools.com #MicrosoftTeams #AtomicStealer #DataBreaches #Malwarebytes #Breadcrumbs #Ransomware #Google.com #@htmalgae #Rilide
-
‘Snatch’ Ransom Group Exposes Visitor IP Addresses
https://krebsonsecurity.com/2023/09/snatch-ransom-group-exposes-visitor-ip-addresses/
#TrustwaveSpiderlabs #Ne'er-Do-WellNews #MihailKolesnikov #8BaseRansomware #DomainTools.com #MicrosoftTeams #AtomicStealer #DataBreaches #Malwarebytes #Breadcrumbs #Ransomware #Google.com #@htmalgae #Rilide
-
Malvertising-Kampagne will Mac-Nutzern #AtomicStealer unterjubeln | Security https://www.heise.de/news/Malvertising-Kampagne-will-Mac-Nutzern-Atomic-Stealer-unterjubeln-9298637.html #cryptocurrencies #cryptocurrency
-
This development comes as macOS systems are increasingly becoming viable targets for malware attacks.