Hackers Used EvilTokens, ClickFix Campaign to Attack Claude Code Users with AMOS Stealer
ID: e52d9dfb-638d-57be-be2f-811ad5e4c4bd
STIX ID: report--e52d9dfb-638d-57be-be2f-811ad5e4c4bd
Feed Name: cybersecurityNews.com
In March 2026, two distinct campaigns were observed: EvilTokens leverages Microsoft’s OAuth Device Code flow and Phishing-as-a-Service automation to obtain OAuth tokens (bypassing MFA and enabling persistent access via PRTs), and a ClickFix campaign delivered the AMOS macOS infostealer via poisoned Google Ads and fake AI-tool documentation, harvesting credentials, Keychain data, and deploying a persistent WebSocket reverse shell; the report provides IoCs, sector targeting, and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
