logo

Hackers Used EvilTokens, ClickFix Campaign to Attack Claude Code Users with AMOS Stealer

ID: e52d9dfb-638d-57be-be2f-811ad5e4c4bd

STIX ID: report--e52d9dfb-638d-57be-be2f-811ad5e4c4bd

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-04-08

Date Updated: 2026-04-21

Author: Balaji N

...
...

In March 2026, two distinct campaigns were observed: EvilTokens leverages Microsoft’s OAuth Device Code flow and Phishing-as-a-Service automation to obtain OAuth tokens (bypassing MFA and enabling persistent access via PRTs), and a ClickFix campaign delivered the AMOS macOS infostealer via poisoned Google Ads and fake AI-tool documentation, harvesting credentials, Keychain data, and deploying a persistent WebSocket reverse shell; the report provides IoCs, sector targeting, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.