Observed Atomic macOS Stealer Infection Chain and IOCs
A SANS Internet Storm Center lab report documents an observed Atomic macOS Stealer infection chain: a ClickFix lure at getmacouscloud[.]com directs users to paste a command into Terminal, which runs a base64-encoded dropper. The report provides network and file indicators for defenders.
Affected
SANS Internet Storm Center documented an Atomic macOS Stealer (AMOS) infection observed in its lab. The report is an infection-chain and indicator analysis of that sample, rather than an assessment of the breadth of an AMOS campaign.
Delivery began at getmacouscloud[.]com, where a ClickFix-style lure instructed the visitor to copy and paste a command into macOS Terminal. That command decoded and executed a base64-encoded dropper, establishing a clear user-assisted route from the malicious page to AMOS execution.
Useful network indicators from the source include the delivery domain getmacouscloud[.]com and command-and-control address 188.166.78[.]138. The SANS report also provides further domains and file hashes that defenders can use for hunting and retrospective analysis; teams should take the complete values directly from the source report.
Defenders should search for visits to the reported domains, connections to the C2 address, and shell activity associated with pasted, base64-encoded commands. User guidance should emphasise that websites must not instruct visitors to paste commands into Terminal. Any matching host should be isolated and investigated for credential, browser-data and cryptocurrency-wallet exposure.
Sources
- 1.SANS ISC