Odyssey Stealer & AMOS Hit macOS Developers with Fake Homebrew Sites
ID: 5ba12f64-c522-5c27-8175-fff52105fb4d
STIX ID: report--5ba12f64-c522-5c27-8175-fff52105fb4d
Feed Name: Hunt.io Blog
This report documents an active, coordinated campaign targeting macOS developers using fake download portals and clipboard-based social engineering to trick victims into pasting base64-encoded curl commands that install Odyssey Stealer or AMOS; investigators identified 85+ phishing domains, reused SSL certificates and multi-year infrastructure (notably IPs 93.152.230.79 and 195.82.147.38), analyzed payload behavior (privilege escalation attempts, anti-analysis, service manipulation, and credential/crypto theft), and provided IOCs and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
