Threat Actors Leverage ChatGPT to Attack Mac Devices With AMOS InfoStealer
ID: a9384d3e-ee90-50bb-a6ba-abab9a653702
STIX ID: report--a9384d3e-ee90-50bb-a6ba-abab9a653702
Feed Name: cybersecurityNews.com
Threat Score
KROLL researchers observed a malicious campaign delivering the AMOS macOS InfoStealer by abusing sponsored ChatGPT sessions promoted via Google Ads; victims seeking troubleshooting are shown a fake chat that instructs them to paste a terminal command (e.g., curl ... | bash) which downloads and runs a script to install the stealer and persist, enabling theft of browser data, credentials, and session cookies for account takeover or resale.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
