Fake Mac fixes trick users into installing new Shamos infostealer
ID: 9454685b-3274-5580-9436-b86f41919675
STIX ID: report--9454685b-3274-5580-9436-b86f41919675
Feed Name: Bleeping Computer
CrowdStrike observed a new macOS infostealer called 'Shamos' (an AMOS variant) deployed by the criminal group COOKIE SPIDER via ClickFix social-engineering (malicious ads and fake GitHub repos that trick users into pasting Terminal commands). Once executed the malware performs anti-VM checks, collects browser data, Keychain items, Apple Notes, and crypto wallets, packages findings into out.zip for exfiltration, can achieve persistence via a LaunchDaemon when run with sudo, and has been seen attempting infections against over 300 monitored environments; macOS users are advised not to execute untrusted commands found online and to avoid sponsored search results for troubleshooting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
