Threat Actors Weaponize ChatGPT, Grok and Leverages Google Ads to Distribute macOS AMOS Stealer
ID: bfead49f-a28a-5fc8-b583-e351d183eb85
STIX ID: report--bfead49f-a28a-5fc8-b583-e351d183eb85
Feed Name: cybersecurityNews.com
Cybercriminals are leveraging shared AI chatbot conversations on ChatGPT and Grok, boosted by paid Google ads, to promote step-by-step “troubleshooting” instructions that trick macOS users into pasting malicious Terminal commands (the "ClickFix" technique). Those commands download and install the Atomic macOS Stealer (AMOS), which harvests browser passwords, Keychain credentials, crypto wallet seed phrases, and personal files while installing a persistent backdoor; defenders should monitor for unsigned apps requesting passwords, unusual Terminal activity, and unexpected network connections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
