Threat Actors Weaponize ChatGPT and Grok Conversations to Deploy AMOS Stealer
ID: 7d4a5529-3d62-5bc4-b379-8eba9a80d910
STIX ID: report--7d4a5529-3d62-5bc4-b379-8eba9a80d910
Feed Name: cybersecurityNews.com
A December 2025 campaign uses high-ranking ChatGPT/Grok conversation links as authoritative troubleshooting guides to trick macOS users into running base64-encoded Terminal commands that deploy the AMOS stealer. The malware uses living-off-the-land techniques (dscl, sudo -S), installs a LaunchDaemon for persistence, captures credentials silently, and exfiltrates data; defenders should monitor dscl/osascript activity, anomalous curl usage, and the provided file/path indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
