FakeSG campaign, Akira ransomware and AMOS macOS stealer
ID: 9254d28e-a8a8-55b0-8f14-0e958b4c6e03
STIX ID: report--9254d28e-a8a8-55b0-8f14-0e958b4c6e03
Feed Name: Securelist by Kaspersky
This report describes three active crimeware threats: the FakeSG NetSupport RAT distribution campaign that lures users with fake browser-update prompts and delivers obfuscated JS and chained payloads; Akira, a C++ cross-platform ransomware family with Conti-like features and over 60 confirmed infected organizations; and AMOS, a macOS stealer distributed via malvertising that harvests browser data, wallets and files. The report includes technical TTPs, infection vectors, persistence mechanisms and multiple IoCs (file hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
