logo

Threat Actors Weaponize ChatGPT and Grok Conversations to Deploy AMOS Stealer

ID: 7d4a5529-3d62-5bc4-b379-8eba9a80d910

STIX ID: report--7d4a5529-3d62-5bc4-b379-8eba9a80d910

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-10

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A December 2025 campaign uses high-ranking ChatGPT/Grok conversation links as authoritative troubleshooting guides to trick macOS users into running base64-encoded Terminal commands that deploy the AMOS stealer. The malware uses living-off-the-land techniques (dscl, sudo -S), installs a LaunchDaemon for persistence, captures credentials silently, and exfiltrates data; defenders should monitor dscl/osascript activity, anomalous curl usage, and the provided file/path indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.