This technical report details an infection campaign involving the Atomic macOS (AMOS) Stealer, distributed via malicious advertisements that impersonate "Claude Code." The attack utilizes a deceptive "ClickFix" social engineering technique, where victims are tricked into copying and pasting a malicious script into their macOS Terminal under the guise of fixing a software installation issue.
Once the script is executed, the AMOS Stealer is deployed on the system. The malware proceeds to request administrative passwords and various system permissions to facilitate the theft of sensitive data. The report includes links to indicators of compromise (IOCs), network traffic captures (PCAPs), and the associated malware files for further analysis.
Top comments (0)