Observed Atomic macOS Stealer Infection Chain and IOCs
A SANS Internet Storm Center lab report documents an observed Atomic macOS Stealer infection chain: a ClickFix lure at getmacouscloud[.]com directs users to paste a command into Terminal, which runs a base64-encoded dropper. The report provides network and file indicators for defenders.