home.social

#atomicstealer — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #atomicstealer, aggregated by home.social.

fetched live
  1. ClickFix Campaign Targets macOS Users with Atomic Stealer Malware

    A macOS ClickFix campaign spanning over 250 domains now uses browser fingerprinting to hide its fake "Download for macOS" lure from crawlers and researchers, while still serving it to genuine Mac users who are tricked into running a Terminal command that deploys the AMOS infostealer.

    Pulse ID: 6a74853991cc8881d222ead0
    Pulse Link: otx.alienvault.com/pulse/6a748
    Pulse Author: cryptocti
    Created: 2026-08-06 12:59:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AMOS #Atomic #AtomicStealer #Browser #CyberSecurity #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #bot #cryptocti

  2. ClickFix Campaign Targets macOS Users with Atomic Stealer Malware

    A macOS ClickFix campaign spanning over 250 domains now uses browser fingerprinting to hide its fake "Download for macOS" lure from crawlers and researchers, while still serving it to genuine Mac users who are tricked into running a Terminal command that deploys the AMOS infostealer.

    Pulse ID: 6a74853991cc8881d222ead0
    Pulse Link: otx.alienvault.com/pulse/6a748
    Pulse Author: cryptocti
    Created: 2026-08-06 12:59:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AMOS #Atomic #AtomicStealer #Browser #CyberSecurity #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #bot #cryptocti

  3. From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

    Microsoft Threat Intelligence identified a macOS ClickFix operation distributing infostealers including MacSync and Atomic Stealer through over 250 algorithmically generated domains. The campaign evolved from openly displaying malicious content to implementing server-side browser fingerprinting that only reveals lures to visitors whose environment matches genuine macOS browsers. The fingerprinting gate collects browser attributes, hardware details via WebGL, and environmental characteristics to filter out crawlers and sandboxes. Victims are shown fake download pages with Terminal commands that retrieve remote scripts, ultimately deploying AMOS infostealer to harvest credentials, browser data, cryptocurrency wallets, and authentication stores. This Traffic Distribution System approach significantly reduces visibility for security researchers and automated analysis tools while maintaining access to intended targets. The operation represents a notable shift in tradecraft, adding sophisticated cloaking to exis...

    Pulse ID: 6a73869b069fb3586fddadf9
    Pulse Link: otx.alienvault.com/pulse/6a738
    Pulse Author: AlienVault
    Created: 2026-08-05 18:53:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AMOS #Atomic #AtomicStealer #Browser #CyberSecurity #ICS #InfoSec #InfoStealer #Mac #MacOS #Microsoft #OTX #OpenThreatExchange #RAT #bot #cryptocurrency #AlienVault

  4. From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

    Microsoft Threat Intelligence identified a macOS ClickFix operation distributing infostealers including MacSync and Atomic Stealer through over 250 algorithmically generated domains. The campaign evolved from openly displaying malicious content to implementing server-side browser fingerprinting that only reveals lures to visitors whose environment matches genuine macOS browsers. The fingerprinting gate collects browser attributes, hardware details via WebGL, and environmental characteristics to filter out crawlers and sandboxes. Victims are shown fake download pages with Terminal commands that retrieve remote scripts, ultimately deploying AMOS infostealer to harvest credentials, browser data, cryptocurrency wallets, and authentication stores. This Traffic Distribution System approach significantly reduces visibility for security researchers and automated analysis tools while maintaining access to intended targets. The operation represents a notable shift in tradecraft, adding sophisticated cloaking to exis...

    Pulse ID: 6a73869b069fb3586fddadf9
    Pulse Link: otx.alienvault.com/pulse/6a738
    Pulse Author: AlienVault
    Created: 2026-08-05 18:53:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AMOS #Atomic #AtomicStealer #Browser #CyberSecurity #ICS #InfoSec #InfoStealer #Mac #MacOS #Microsoft #OTX #OpenThreatExchange #RAT #bot #cryptocurrency #AlienVault

  5. 250+ macOS ClickFix Domains Use Browser Fingerprinting to Hide Atomic Stealer Attacks

    Indicators extracted from public reporting. Source: cybersecuritynews.com/158536-2

    Pulse ID: 6a7421ea3cb7d6ca6a2de878
    Pulse Link: otx.alienvault.com/pulse/6a742
    Pulse Author: CyberHunter_NL
    Created: 2026-08-06 05:55:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Atomic #AtomicStealer #Browser #CyberSecurity #HTTP #HTTPS #InfoSec #Mac #MacOS #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  6. 250+ macOS ClickFix Domains Use Browser Fingerprinting to Hide Atomic Stealer Attacks

    Indicators extracted from public reporting. Source: cybersecuritynews.com/158536-2

    Pulse ID: 6a7421ea3cb7d6ca6a2de878
    Pulse Link: otx.alienvault.com/pulse/6a742
    Pulse Author: CyberHunter_NL
    Created: 2026-08-06 05:55:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Atomic #AtomicStealer #Browser #CyberSecurity #HTTP #HTTPS #InfoSec #Mac #MacOS #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  7. MacOS ClickFix Attack Exploits Script Editor to Evade Apple Warnings

    The cat-and-mouse game continues: after Apple added security warnings to Terminal, attackers behind the Atomic Stealer family adapted their ClickFix attack to exploit Script Editor instead. This latest move shows how adversaries constantly evolve to evade detection.

    osintsights.com/macos-clickfix

    #Macos #ClickfixAttack #AtomicStealer #MalwareOperations #EmergingThreats

  8. ah ben voilà, je me disais : quand est-ce que le bon vieux AppleScript allait être intégré dans les campagnes ClickFix visant macOS ?

    Il aura fallu qu’Apple introduise sa nouvelle fonctionnalité de protection du copier/coller dans le Terminal
    ( d'ailleurs et comme d'hab 😁 « largement inspirée », par le travail de Patrick Wardle dans blockblock :
    objective-see.org/blog/blog_0x )

    …pour que la campagne Atomic Stealer passe à Script Editor.
    ⬇️
    ClickFix technique uses Script Editor instead of Terminal on macOS
    Jamf Threat Labs discovered a ClickFix-style macOS attack that abuses the applescript:// URL scheme to launch Script Editor and deliver an Atomic Stealer infostealer payload — bypassing Terminal entirely.
    👇
    jamf.com/blog/clickfix-macos-s

    #cyberveille #macos #atomicstealer

  9. Forschende von Jamf Threat berichten heute über eine neue Variante einer bekannten Cyberangriffsmethode. Der Angriff zielt auf Mac-Nutzende ab und nutzt eine ziemlich geschickte Täuschung, um Schadsoftware auf den Mac zu schleusen.

    Mehr: digiprax.maniabel.work/archiv/

    #infostealer #AtomicStealer #jamf #infosec #up2date #macOS #ScriptEditor #ClickFix

  10. macOS Users Targeted in ClickFix Malware Campaign

    macOS users are being targeted in a sneaky new malware campaign called ClickFix, which tricks them into executing malicious commands by abusing the Script Editor and Terminal tools. This latest attack raises a pressing question: how can we trust our trusted tools when they're being exploited by hackers?

    osintsights.com/macos-users-ta

    #Macos #AtomicStealer #Clickfix #MalwareOperations #EmergingThreats

  11. 🚨 Fake Malwarebytes, LastPass & 70+ brands abused on GitHub to spread Atomic Stealer (AMOS).
    🔹 Fake repos + SEO + sponsored ads = malware installs
    🔹 Copy-paste terminal commands (curl … | bash) deliver the payload instantly
    🔹 Brands targeted include password managers, fintech apps, and dev tools
    ⚠️ Another reminder: only trust official developer sites.
    💬 Do you think GitHub & Google should be held more accountable for catching these campaigns earlier?

    Follow @technadu for #CyberSecurity insights.

    #Malware #AtomicStealer #AMOS #Infostealer #MacOS #Malwarebytes #LastPass #GitHubSecurity

  12. 🚨 macOS users are being hit with a widespread infostealer campaign.
    LastPass warns that hackers are using fake GitHub repos + SEO tricks to deliver the Atomic Stealer (AMOS) malware.

    ⚠️ Impersonated brands: password managers, banks, crypto wallets, AI tools
    ⚠️ Ongoing since July, with multiple fake repos removed
    ⚠️ Trust in GitHub & Google Ads is being weaponized
    💬 How do you think platforms can balance openness with stronger malware detection?
    🔔 Follow @technadu for daily cyber threat updates.

    #macOS #Infostealer #AtomicStealer #AMOS #GitHubThreats #LastPass #Cybercrime #CyberResilience #TechNadu

  13. Malicious ad for Arc browser -> #AtomicStealer

    arcthost[.]org
    arc-download[.]com
    zestyahhdog[.]com/Arc12645413[.]dmg

    C2: 79.137.192[.]4/p2p

    #malvertising #threatintel

  14. Malicious ad for Arc browser -> #AtomicStealer

    arcthost[.]org
    arc-download[.]com
    zestyahhdog[.]com/Arc12645413[.]dmg

    C2: 79.137.192[.]4/p2p

    #malvertising #threatintel

  15. 🚨 Malicious Zoom ad for Mac & Windows 🚨

    Google ad ➡️ Fake Zoom site ➡️ Payload🔑

    🤓 Fake advertiser: Jessica Babcok
    ⚠️ Zoom site: zocmstranslate[.]com

    🔹Mac (#atomicstealer, C2: 5.182.86[.]95)
    🔹Windows (#LummaStealer, C2: stiffraspyofkwsl[.]shop)

    #malvertising #threatintel

  16. 🚨 Malicious Zoom ad for Mac & Windows 🚨

    Google ad ➡️ Fake Zoom site ➡️ Payload🔑

    🤓 Fake advertiser: Jessica Babcok
    ⚠️ Zoom site: zocmstranslate[.]com

    🔹Mac (#atomicstealer, C2: 5.182.86[.]95)
    🔹Windows (#LummaStealer, C2: stiffraspyofkwsl[.]shop)

    #malvertising #threatintel

  17. Jamf warns of two ongoing infostealer campaigns target macOS environments: Atomic Stealer being spread through Sponsored Ads (malvertising) and the attempted execution of an unsigned executable with a bad hash from Meethub. "Many of these stealers are targeting individuals involved in the crypto industry with a focus on harvesting credentials along with data from various crypto wallets." Attack chains described, IOC provided. 🔗 jamf.com/blog/infostealers-pos

    #infostealer #threatintel #IOC #AtomicStealer #Meethub

  18. Jamf warns of two ongoing infostealer campaigns target macOS environments: Atomic Stealer being spread through Sponsored Ads (malvertising) and the attempted execution of an unsigned executable with a bad hash from Meethub. "Many of these stealers are targeting individuals involved in the crypto industry with a focus on harvesting credentials along with data from various crypto wallets." Attack chains described, IOC provided. 🔗 jamf.com/blog/infostealers-pos

    #infostealer #threatintel #IOC #AtomicStealer #Meethub

  19. It’s not all rosy in the land of macOS, as a new malware variant has been discovered that explicitly targets Apple users. Luckily, there are things you can do to protect yourself.

    #apple #macos #malware #atomicstealer
    tchlp.com/46CY9GC

  20. It’s not all rosy in the land of macOS, as a new malware variant has been discovered that explicitly targets Apple users. Luckily, there are things you can do to protect yourself.

    #apple #macos #malware #atomicstealer
    tchlp.com/46CY9GC

  21. Only 10 days into October and still lots of new #macOS #apple #AtomicStealer variants all over VT.
    57 and counting...
    Want to play? See the updated #malware IOCs for October here:
    https:/s1.ai/amos

  22. Only 10 days into October and still lots of new #macOS #apple #AtomicStealer variants all over VT.
    57 and counting...
    Want to play? See the updated #malware IOCs for October here:
    https:/s1.ai/amos