home.social

#macossecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #macossecurity, aggregated by home.social.

  1. Nueva campaña ClickFix "Claude Code on Mac" de malware para macOS usando anuncios de Google y chats compartidos legítimos en Claude

    mecambioamac.com/campana-click

  2. ClickFix campaigns are now leveraging LLM-generated public artifacts for malware distribution.

    Per Moonlock Lab and AdGuard:
    • Abuse of Claude artifact pages
    • Google Ads search poisoning
    • Obfuscated shell execution (base64 decode → zsh)
    • Second-stage loader for MacSync infostealer
    • Hardcoded API key + token-protected C2
    • AppleScript (osascript) handling data theft
    • Archive staging at /tmp/osalogging.zip
    • Multi-attempt POST exfiltration

    Previous campaigns exploited ChatGPT and Grok sharing features.
    LLM trust is now an operational risk vector.
    Should EDR flag suspicious AI-guided shell patterns?

    Source: bleepingcomputer.com/news/secu

    Engage below.
    Follow @technadu for deep technical threat analysis.

    #ThreatIntel #MacOSSecurity #Infostealer #C2Traffic #ClickFix #LLMSecurity #MalwareAnalysis #AppSec #BlueTeam #EDR #ThreatHunting #CyberThreats #ZeroTrust

  3. ClickFix campaigns are now leveraging LLM-generated public artifacts for malware distribution.

    Per Moonlock Lab and AdGuard:
    • Abuse of Claude artifact pages
    • Google Ads search poisoning
    • Obfuscated shell execution (base64 decode → zsh)
    • Second-stage loader for MacSync infostealer
    • Hardcoded API key + token-protected C2
    • AppleScript (osascript) handling data theft
    • Archive staging at /tmp/osalogging.zip
    • Multi-attempt POST exfiltration

    Previous campaigns exploited ChatGPT and Grok sharing features.
    LLM trust is now an operational risk vector.
    Should EDR flag suspicious AI-guided shell patterns?

    Source: bleepingcomputer.com/news/secu

    Engage below.
    Follow @technadu for deep technical threat analysis.

    #ThreatIntel #MacOSSecurity #Infostealer #C2Traffic #ClickFix #LLMSecurity #MalwareAnalysis #AppSec #BlueTeam #EDR #ThreatHunting #CyberThreats #ZeroTrust

  4. ClickFix campaigns are now leveraging LLM-generated public artifacts for malware distribution.

    Per Moonlock Lab and AdGuard:
    • Abuse of Claude artifact pages
    • Google Ads search poisoning
    • Obfuscated shell execution (base64 decode → zsh)
    • Second-stage loader for MacSync infostealer
    • Hardcoded API key + token-protected C2
    • AppleScript (osascript) handling data theft
    • Archive staging at /tmp/osalogging.zip
    • Multi-attempt POST exfiltration

    Previous campaigns exploited ChatGPT and Grok sharing features.
    LLM trust is now an operational risk vector.
    Should EDR flag suspicious AI-guided shell patterns?

    Source: bleepingcomputer.com/news/secu

    Engage below.
    Follow @technadu for deep technical threat analysis.

    #ThreatIntel #MacOSSecurity #Infostealer #C2Traffic #ClickFix #LLMSecurity #MalwareAnalysis #AppSec #BlueTeam #EDR #ThreatHunting #CyberThreats #ZeroTrust

  5. ClickFix campaigns are now leveraging LLM-generated public artifacts for malware distribution.

    Per Moonlock Lab and AdGuard:
    • Abuse of Claude artifact pages
    • Google Ads search poisoning
    • Obfuscated shell execution (base64 decode → zsh)
    • Second-stage loader for MacSync infostealer
    • Hardcoded API key + token-protected C2
    • AppleScript (osascript) handling data theft
    • Archive staging at /tmp/osalogging.zip
    • Multi-attempt POST exfiltration

    Previous campaigns exploited ChatGPT and Grok sharing features.
    LLM trust is now an operational risk vector.
    Should EDR flag suspicious AI-guided shell patterns?

    Source: bleepingcomputer.com/news/secu

    Engage below.
    Follow @technadu for deep technical threat analysis.

    #ThreatIntel #MacOSSecurity #Infostealer #C2Traffic #ClickFix #LLMSecurity #MalwareAnalysis #AppSec #BlueTeam #EDR #ThreatHunting #CyberThreats #ZeroTrust

  6. Safari 26.3 patches 6 critical vulnerabilities CFNetwork flaw allowed arbitrary file writing. AdwaitX analyzes WebKit security fixes for macOS Sonoma and Sequoia users. Update now to protect browsing data #AdwaitX #Safari #macOSSecurity

    adwaitx.com/safari-26-3-securi

  7. A new macOS-focused AMOS infostealer campaign is redirecting users to shared ChatGPT and Grok conversations via malicious Google ads. The chats contain Terminal commands that decode into a script installing AMOS with elevated privileges.

    AMOS then targets crypto wallets, browser data, Keychain items, and more - with persistence handled through LaunchDaemons and AppleScripts.

    This campaign highlights how AI platforms and search ads can be misused as delivery mechanisms.

    What safeguards should exist to prevent similar abuse?

    Source:
    bleepingcomputer.com/news/secu

    Follow TechNadu for more threat-intel updates.

    #Infosec #ThreatIntel #macOSSecurity #AMOS #Malware #DigitalSafety #AIChatSecurity #CyberAwareness

  8. A new macOS-focused AMOS infostealer campaign is redirecting users to shared ChatGPT and Grok conversations via malicious Google ads. The chats contain Terminal commands that decode into a script installing AMOS with elevated privileges.

    AMOS then targets crypto wallets, browser data, Keychain items, and more - with persistence handled through LaunchDaemons and AppleScripts.

    This campaign highlights how AI platforms and search ads can be misused as delivery mechanisms.

    What safeguards should exist to prevent similar abuse?

    Source:
    bleepingcomputer.com/news/secu

    Follow TechNadu for more threat-intel updates.

    #Infosec #ThreatIntel #macOSSecurity #AMOS #Malware #DigitalSafety #AIChatSecurity #CyberAwareness

  9. A new macOS-focused AMOS infostealer campaign is redirecting users to shared ChatGPT and Grok conversations via malicious Google ads. The chats contain Terminal commands that decode into a script installing AMOS with elevated privileges.

    AMOS then targets crypto wallets, browser data, Keychain items, and more - with persistence handled through LaunchDaemons and AppleScripts.

    This campaign highlights how AI platforms and search ads can be misused as delivery mechanisms.

    What safeguards should exist to prevent similar abuse?

    Source:
    bleepingcomputer.com/news/secu

    Follow TechNadu for more threat-intel updates.

    #Infosec #ThreatIntel #macOSSecurity #AMOS #Malware #DigitalSafety #AIChatSecurity #CyberAwareness

  10. El equipo de Jamf Threat Labs nos trae un informe sobre : un sofisticado programa para robar información de macOS suplantando al software de Aviorrok

    mecambioamac.com/digitstealer-

  11. A seemingly routine tool update could be a trap—malware like AMOS and Odyssey are stealthily targeting macOS developers and snatching credentials and source code. Are you prepared for this new wave of cyber threats?

    thedefendopsdiaries.com/the-ri

    #macossecurity
    #infostealers
    #cyberthreats
    #amosmalware
    #odysseymalware

  12. A seemingly routine tool update could be a trap—malware like AMOS and Odyssey are stealthily targeting macOS developers and snatching credentials and source code. Are you prepared for this new wave of cyber threats?

    thedefendopsdiaries.com/the-ri

    #macossecurity
    #infostealers
    #cyberthreats
    #amosmalware
    #odysseymalware

  13. A seemingly routine tool update could be a trap—malware like AMOS and Odyssey are stealthily targeting macOS developers and snatching credentials and source code. Are you prepared for this new wave of cyber threats?

    thedefendopsdiaries.com/the-ri

    #macossecurity
    #infostealers
    #cyberthreats
    #amosmalware
    #odysseymalware

  14. A seemingly routine tool update could be a trap—malware like AMOS and Odyssey are stealthily targeting macOS developers and snatching credentials and source code. Are you prepared for this new wave of cyber threats?

    thedefendopsdiaries.com/the-ri

    #macossecurity
    #infostealers
    #cyberthreats
    #amosmalware
    #odysseymalware

  15. ⏳ In less than 15 days, we'll be live at #BlackHat USA 2025 with our 2-day hands-on macOS Threat Detection & Incident Response training. 🍏

    Built for defenders of macOS - attack simulations, forensics, and incident response you can actually use in the field

    🚀 Seats are filling fast -

    🗓️ Aug 2–3: shorturl.at/YVTq9

    🗓️ Aug 4–5: shorturl.at/sktoB

    👉 Share with someone who needs this!

    #DFIR #macOS #BlueTeam #IncidentResponse #ThreatDetection #macOSSecurity #BlackHatUSA #BHUSA