Fake Microsoft Teams for Mac delivers Atomic Stealer
ID: c80b3d84-8789-58c3-9f83-12159e256ab2
STIX ID: report--c80b3d84-8789-58c3-9f83-12159e256ab2
Feed Name: Malwarebytes Blog
Threat Score
Malwarebytes describes an active malvertising campaign that lures macOS users with a fake Microsoft Teams ad to download a malicious DMG that installs Atomic Stealer (OSX.AtomStealer). The campaign uses profiling, cloaking domains, unique per-victim payloads, and instructions to bypass macOS unsigned-app protections to harvest keychain passwords and files, then exfiltrates encoded data to a remote C2 (147.45.43.136); indicators and mitigations are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
