macOS ClickFix Crimekit Uses Polygon Smart Contracts to Deploy AMOS Stealer and XMRig Miner
ID: 8b5a3a01-f168-5e9c-88ae-a5a2c3f2acec
STIX ID: report--8b5a3a01-f168-5e9c-88ae-a5a2c3f2acec
Feed Name: GBHackers
This report details a macOS-targeted campaign that lures victims with a fake CAPTCHA/ClickFix page to execute a curl|bash chain from a Cloudflare Worker, installs a persistent LaunchAgent loader which resolves and rotates C2 via a Polygon smart contract (EtherHiding), and deploys an AMOS infostealer, persistent backdoor agent, and XMRig miner; it includes IoCs and suggested detection hunts (Terminal-launched curl|bash, osascript usage, new LaunchAgents, eth_call to the identified contract).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
