logo

FakeSG campaign, Akira ransomware and AMOS macOS stealer

ID: 9254d28e-a8a8-55b0-8f14-0e958b4c6e03

STIX ID: report--9254d28e-a8a8-55b0-8f14-0e958b4c6e03

Feed Name: Securelist by Kaspersky

Threat Score
70/100

Date Published: 2023-12-13

Date Updated: 2026-04-29

Author: GReAT

...
...

This report describes three active crimeware threats: the FakeSG NetSupport RAT distribution campaign that lures users with fake browser-update prompts and delivers obfuscated JS and chained payloads; Akira, a C++ cross-platform ransomware family with Conti-like features and over 60 confirmed infected organizations; and AMOS, a macOS stealer distributed via malvertising that harvests browser data, wallets and files. The report includes technical TTPs, infection vectors, persistence mechanisms and multiple IoCs (file hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.