New Atomic MacOS Stealer For Sale On Telegram
ID: 648a2465-7d1a-589d-8c62-02803699c401
STIX ID: report--648a2465-7d1a-589d-8c62-02803699c401
Feed Name: Cyble Blog
Atomic macOS Stealer (AMOS) is a Golang-based macOS information stealer distributed via a malicious .dmg installer and actively marketed on Telegram; it harvests keychain passwords, browser autofills/cookies/passwords, crypto wallet files and extensions, user files (Desktop/Documents), and system identifiers, then compresses and exfiltrates the data to a C2 (http://amos-malware.ru/sendlog) and Telegram channels. The report includes a FUD sample hash, targeted browser/extension lists, screenshots of functionality and the C2 panel, MITRE ATT&CK mappings, IoCs, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
