Atomic Stealer Gets an Upgrade - Targeting Mac Users with Encrypted Payload
ID: 64048ab0-7c7d-52e1-a23c-518e1d991dac
STIX ID: report--64048ab0-7c7d-52e1-a23c-518e1d991dac
Feed Name: The Hacker News
Threat Score
Researchers have identified an updated macOS information stealer called Atomic (AMOS) that introduced payload encryption and obfuscation to bypass detection. The malware, sold as a commercial service (now up to $3,000/month), steals Keychain passwords, session cookies, files, crypto wallets, system metadata and the machine password via fake prompts, and is being distributed via malvertising, compromised sites, and fraudulent Slack disk images or loaders like EugenLoader.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
