Malware

AMOS

Also known as: Atomic macOS Stealer

Indicators of Compromise 58

Domain applefilevault[.]com Domain bonoud[.]com Domain chatgpt[.]com Domain claude[.]ai Domain download[.]setup-service[.]com Domain filecopperbasket[.]sbs Domain filmoraus[.]com Domain glot[.]io Domain grok[.]com Domain gsnc[[.]]eu Domain gsocket[.]io Domain homebrewclubs[.]org Domain homebrewfaq[.]org Domain homebrewonline[.]org Domain homebrewupdate[.]org Domain install[.]app-distribution[.]net Domain laosji[.]net Domain logmeeine[.]com Domain logmeln[.]com Domain moonsand[[.]]store Domain openclawcli[.]vercel[.]app Domain rentry[.]co Domain sites-phantom[.]com Domain tradingviewen[.]com Filename /curl/<id> Filename Apple Sync Filename ComponentTask33-4d14e6ac.msi Filename HDUtil.exe Filename SKILL.md Filename com.authirity.plist Filename com.chromer.plist Filename go.bat Filename goyim Filename hwid.dat Filename iCloud Filename install.sh Filename mode:"php" Filename protobuf.dll Filename script.sh Filename termsrv.dll GitHub Repo Ddoy233/openclawcli GitHub Repo GSocket GitHub Repo SQL Server Management Studio GitHub Repo skills.sh SHA-256 818aea6143282b352fdfdc0f3ebf77a36e54eb3befb5cad1a355a99ab97c6aa7 SHA-256 881ce5cb124c4d2e814783724cc1388f6a1cbf6eee274c3f3366e77ba3503ad7 SHA-256 b30eaed1f7478c28f4ec50d07ed5ef014ffbc4b2bc5a38d689ba9f7abb5e19c2 SHA-256 b6c7e0bf573b1c7d9d3a05eb08d26579199515b847df984862805f44a7af8007 SHA-256 ebb73dbb5aac1f6fe1a88e8f26126a1e1aa34c9f3345ad4345189b40d9bf1d1d SHA-256 f4e41aa269c88bf11a2022701a9cf41e9a186aa1b224d837c31bf34e0b875d0e IP 195[.]82[.]147[.]38 IP 2[.]26[.]75[.]16 IP 91[.]92[.]242[.]30 IP 93[.]152[.]230[.]79 IP gsnc[[.]]eu Package GSocket Package Rilide Registry User The Hacker's Choice

MITRE ATT&CK TTPs 40

T1003
OS Credential Dumping
Credential Access
T1013
T1013
T1016
System Network Configuration Discovery
Discovery
T1021.001
Remote Desktop Protocol
Lateral Movement
T1027
Obfuscated Files or Information
Defense Evasion
T1048
Exfiltration Over Alternative Protocol
Exfiltration
T1053.005
Scheduled Task
Execution
T1055
Process Injection
Defense Evasion
T1056.001
Keylogging
Collection
T1056.002
GUI Input Capture
Collection
T1059.001
PowerShell
Execution
T1059.003
Windows Command Shell
Execution
T1059.004
Unix Shell
Execution
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1069.001
Local Groups
Discovery
T1070.004
File Deletion
Defense Evasion
T1071
Application Layer Protocol
Command And Control
T1071.001
Web Protocols
Command And Control
T1071.004
DNS
Command And Control
T1078
Valid Accounts
Defense Evasion
T1078.001
Default Accounts
Defense Evasion
T1078.004
Cloud Accounts
Defense Evasion
T1082
System Information Discovery
Discovery
T1083
File and Directory Discovery
Discovery
T1086
T1086
T1090
Proxy
Command And Control
T1105
Ingress Tool Transfer
Command And Control
T1136.001
Local Account
Persistence
T1204.002
Malicious File
Execution
T1210
Exploitation of Remote Services
Lateral Movement
T1218.011
Rundll32
Defense Evasion
T1485
Data Destruction
Impact
T1497
Virtualization/Sandbox Evasion
Defense Evasion
T1499.004
Application or System Exploitation
Impact
T1543.001
Launch Agent
Persistence
T1547.001
Registry Run Keys / Startup Folder
Persistence
T1548.002
Bypass User Account Control
Privilege Escalation
T1557
Adversary-in-the-Middle
Credential Access
T1566
Phishing
Initial Access
T1647
Plist File Modification
Defense Evasion

Source Articles

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Threat actors are using ClickFix-style social engineering lures to distribute a new remote access trojan (RAT) named ChainScript, which provides extensive remote control capabilities including command execution, file operations, screenshot capture, and cryptocurrency wallet theft. The malware uses a malicious Windows installer disguised as legitimate software (e.g., Spotify) to deploy a Node.js-based JavaScript agent via PowerShell and VBScript stages, establishing persistence through scheduled tasks and Registry Run keys. ChainScript employs a novel C2 discovery mechanism leveraging a Polygon blockchain smart contract to dynamically rotate WebSocket-based command-and-control infrastructure, enhancing resilience against takedowns. This campaign overlaps with another abuse of HBO Max's Reddit account, distributing macOS and Windows malware such as MacSync, Atomic Stealer, and Amatera Stealer under the PasteSwitch operation.
hacker-news ·1w ago
How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
Threat actors are exploiting trusted AI platforms such as Claude, ChatGPT, and Grok by weaponizing shareable content features to distribute malware. Attackers created malicious Claude Artifacts and shared conversations that mimic legitimate software install guides or troubleshooting advice, hosted on the official domains of these platforms, to bypass user skepticism. These lures trick users into downloading SectopRAT, MacSync stealer, or AMOS stealer via malicious commands or redirects, leveraging the inherent trust in well-known domains. The campaigns are short-lived but effective, relying on SEO poisoning and sponsored search results to increase visibility.
bleeping-computer ·3w ago
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
A macOS-focused threat operation leveraging over 250 front-end domains employs browser fingerprinting to selectively serve malware lures to genuine Mac users while evading crawlers and sandbox environments. The fingerprinting script collects navigator properties, screen dimensions, WebGL signals, timezone, iframe detection, touch support, developer console activity, and codec capability checks to determine if the visitor is a real Mac user. Qualified users are presented with a fake GitHub-themed 'Download for macOS' page that delivers the Atomic Stealer (AMOS) infostealer via an obfuscated Terminal command. The command retrieves additional scripts from a /curl/<id> endpoint and executes payloads that target credentials, browser data, authentication stores, cryptocurrency wallets, and sensitive files.
hacker-news ·1mo ago
Dev Machine Guard Now Inventories AI Agent Skills on Developer Machines
The article details an active threat involving malicious AI agent skills used in supply chain attacks, specifically citing the ClawHavoc campaign which distributed the Atomic Stealer (AMOS) malware through compromised skills. These skills, which can execute scripts with developer privileges, have been found to contain malicious payloads capable of exfiltrating SSH keys and other sensitive data. The article also references the Miasma worm and Cline v2.3.0 compromise as part of a broader trend of attacks targeting AI coding agent ecosystems. Security teams are warned about the lack of visibility into skill inventories, enabling unchecked propagation of malicious or vulnerable skills across developer environments.
step-security ·2mo ago
Odyssey Stealer & AMOS Hit macOS Developers with Fake Homebrew Sites
A macOS-targeted campaign dubbed 'Odyssey Stealer & AMOS' is actively distributing malware to developers through fake software download sites impersonating trusted platforms like Homebrew, TradingView, and LogMeIn. Attackers use social engineering tactics, including clipboard manipulation and base64-encoded commands, to trick users into executing malicious payloads. The campaign leverages reused infrastructure, including IP addresses and SSL certificates, to distribute stealer malware capable of harvesting system data, browser credentials, and cryptocurrency wallets.
hunt.io
New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password
ClickLock is a new macOS infostealer that uses social engineering via a fake Cloudflare CAPTCHA to trick users into pasting a malicious command into Terminal. Upon refusal to enter credentials, it initiates aggressive app-killing loops every 210ms to coerce compliance. It steals login passwords, browser credentials, crypto wallets, and Keychain data, exfiltrating via Telegram bots. The malware uses compromised websites for payload delivery and a modified open-source backdoor, with persistence via LaunchAgents.
hacker-news ·2mo ago
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
OkoBot is a malware framework targeting Windows users, active since April 2025, that injects phishing pages into legitimate cryptocurrency wallet applications like Ledger Live and Trezor Suite to steal recovery phrases. One of its modules, SeedHunter, hooks into Electron-based apps and waits for hardware wallet connections before displaying a malicious recovery page. The framework uses trojanized software and phishing lures to gain access, establishes persistent remote access via SSH and RDP, and deploys multiple surveillance and data-stealing plugins. Kaspersky attributes the campaign to an unknown actor but notes Russian-language artifacts and targeting patterns.
hacker-news ·2mo ago
OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat
OpenClaw's skill marketplace, ClawHub, has become a vector for AI supply chain attacks involving malicious skills that distribute infostealers, evade detection through file padding, and enable financial fraud via affiliate injection and front-running schemes. Multiple malicious skills were discovered between February and May 2026, leveraging paste-site redirects, C2 infrastructure, and dynamic payload delivery. These threats bypassed automated screening tools like VirusTotal and ClawScan, highlighting weaknesses in current detection mechanisms. Palo Alto Networks has collaborated with ClawHub and NVIDIA to improve skill verification and protect customers through advanced security services.
unit42 ·3mo ago