logo

Fake Microsoft Teams for Mac delivers Atomic Stealer

ID: c80b3d84-8789-58c3-9f83-12159e256ab2

STIX ID: report--c80b3d84-8789-58c3-9f83-12159e256ab2

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2024-07-12

Date Updated: 2026-04-28

...
...

Malwarebytes describes an active malvertising campaign that lures macOS users with a fake Microsoft Teams ad to download a malicious DMG that installs Atomic Stealer (OSX.AtomStealer). The campaign uses profiling, cloaking domains, unique per-victim payloads, and instructions to bypass macOS unsigned-app protections to harvest keychain passwords and files, then exfiltrates encoded data to a remote C2 (147.45.43.136); indicators and mitigations are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.