logo

Stealers on the Rise: A Closer Look at a Growing macOS Threat

ID: 16f4ed65-50e7-5175-b4c0-bd189aac7fed

STIX ID: report--16f4ed65-50e7-5175-b4c0-bd189aac7fed

Feed Name: Palo Alto Networks Unit 42

Threat Score
75/100

Date Published: 2025-02-04

Date Updated: 2026-04-28

Author: Tom Fakterman, Chen Erlich and Tom Sharon

...
...

This report details a growing wave of macOS infostealers—Atomic (AMOS), Poseidon, and Cthulhu—sold as Malware-as-a-Service and distributed via malvertising, trojanized installers, Google Ads, and spam; it analyzes their AppleScript-based techniques for stealing credentials, browser data, crypto wallets, and notes, provides detection/mitigation guidance (Cortex XDR, XSIAM, WildFire, URL/DNS filtering), and supplies IoCs (SHA256 hashes and C2 IPs) for defenders to act on.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.