Mac Users Beware: Atomic MacOS Stealer Malware Unleashed Through Malvertising Campaign
- Atomic Stealer Malware (AMOS): A new malvertising campaign is distributing an updated version of the macOS malware known as Atomic Stealer or AMOS. This malware, actively maintained and updated by its creators, is being sold for $1000 per month and targets gamers and cryptocurrency users, stealing a wide range of data including keychain passwords, browser data, and files from compromised devices.
- Distribution through Google Ads: The malware is primarily distributed through Google Ads, directing users to fraudulent websites hosting rogue installers when they search for popular software. A notable fraudulent website used in this campaign impersonates the TradingView financial market tracking app, offering downloads for Windows, macOS, and Linux, with the macOS file delivering the AMOS malware.
- Evading macOS Security: Once downloaded, the malware instructs users on how to bypass Apple's Gatekeeper security feature, exploiting the system to exfiltrate stolen data to a server controlled by the attackers. It has evasion capabilities to bypass Gatekeeper protections and is capable of harvesting files and data stored in iCloud keychains and web browsers, including crypto-related browser extensions.
- Targeting Cryptocurrency Users and Gamers: The malware has evolved to target a broader range of operating systems, focusing particularly on gamers and cryptocurrency users. It seeks to steal information related to cryptocurrencies and has a hardcoded list of crypto-related browser extensions to attack. The attackers are leveraging the wide availability of Apple systems in organizations, marking a trend of increasing macOS-targeted attacks.
North Korean Threat Actors Exploit Zero-Day to Target Cybersecurity Experts
- Zero-Day Exploitation: North Korean threat actors have been exploiting a zero-day vulnerability in an unspecified software to target cybersecurity researchers. The vulnerability is currently being patched.
- Sophisticated Social Engineering: The attackers utilized social media platforms such as "X" (formerly Twitter) and Mastodon to build trust with potential targets, engaging them in month-long conversations before moving to encrypted messaging apps like Signal, WhatsApp, or Wire to send malicious files exploiting the zero-day.
- Shellcode and Anti-VM Checks: Upon successful exploitation, the shellcode performs a series of anti-virtual machine checks, transmitting collected data and screenshots back to an attacker-controlled server.
- Collaborative Lures: This is not the first time North Korean actors have used collaboration-themed lures. Previously, they have used GitHub and fake personas to target the cybersecurity sector, inviting targets to collaborate on GitHub repositories and convincing them to execute malicious contents.
- Global Intelligence Gathering: Recent activities suggest a concerted effort by North Korean government-backed groups to gather intelligence globally, targeting defense industries and governments in various countries including Russia, Germany, and Israel, to improve their military capabilities.