logo

Atomic Stealer Strikes & Dead Cookies Restoration Rise

ID: a059e1b4-0885-58be-8c42-96f20d828c1e

STIX ID: report--a059e1b4-0885-58be-8c42-96f20d828c1e

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2026-03-18

Date Updated: 2026-07-17

...
...

CRIL analyzed an active campaign distributing the Atomic macOS Stealer (AMOS) via phishing sites that impersonate macOS applications (Parallels, CleanMyMac, Arc, Pixelmator). The report details technical behavior—password/keychain theft, browser cookie and credential extraction across Chromium-based and Firefox browsers, crypto-wallet targeting, file exfiltration to C2 5.42.65.108:80—provides IOCs (DMG hashes, malicious URLs, C2 IP) and a YARA rule, and highlights a concerning trend: freely shared code to revive expired Chrome cookies which has rapidly been adopted by other stealers, increasing risk of account takeover.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.