City
Epaper

Atomic Stealer malware spread to Mac users via fake browser updates: Report

By IANS | Updated: November 27, 2023 10:55 IST

San Francisco, Nov 27 Threat actors are delivering Atomic Stealer malware, also known as AMOS, to Mac users ...

Open in App

San Francisco, Nov 27 Threat actors are delivering Atomic Stealer malware, also known as AMOS, to Mac users via a fake browser update chain tracked as "ClearFake", a new report has found.

According to the cybersecurity company Malwarebytes, ClearFake is a newer malware campaign that leverages compromised websites to distribute fake browser updates.

"With a growing list of compromised sites at their disposal, the threat actors are able to reach out to a wider audience, stealing credentials and files of interest that can be monetised immediately or repurposed for additional attacks," the researchers said.

On November 17, security researcher Ankit Anubhav observed that ClearFake was dispersed to Mac users as well with a corresponding payload.

The ClearFake campaign began in July of this year, with the goal of targeting Windows users with bogus Chrome update prompts that appear on compromised sites via JavaScript injections.

According to the report, these attacks utilise a Safari update bait along with the standard Chrome overlay.

"The payload is made for Mac users, a DMG file purporting to be a Safari or Chrome update. Victims are instructed on how to open the file which immediately runs commands after prompting for the administrative password," according to the researchers.

In a file accessed by the researchers, they looked at the strings from the malicious application and saw those commands, which include password and file-grabbing capabilities.

In the same file, they found the malware’s command and control server where the stolen data was sent to.

"Because ClearFake has become one of the main social engineering campaigns recently, Mac users should pay particular attention to it. We recommend leveraging web protection tools to block the malicious infrastructure associated with this threat actor," the researchers suggested.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

TechnologyKinetic Green's electric golf cart uses 95 pc Indian parts: CEO Sulajja Firodia Motwani

Other SportsNational 4W Racing Championship boasts 75 entries across categories

BusinessKinetic Green's electric golf cart uses 95 pc Indian parts: CEO Sulajja Firodia Motwani

NationalRowdy-sheeter murder case: K'taka MLA gets police notice, BJP says leaders targeted

NationalWest Bengal: Wave of enthusiasm among Durgapur residents ahead of PM Modi's much-anticipated rally

International Realted Stories

InternationalPakistan's child protection crisis deepens amid legal paralysis, social complicity in Khyber Pakhtunkhwa

InternationalSouth Korea: Court begins hearing on legality of ex-President Yoon's arrest

InternationalPakistan accused of silencing Baloch Voices as families protest enforced disappearances in Islamabad

InternationalHRCP holds national roundtable on alarming curbs to freedom of expression in Pakistan

InternationalNetanyahu told Trump he made "mistake", says White House after strike on Gaza Church