City
Epaper

Atomic Stealer malware spread to Mac users via fake browser updates: Report

By IANS | Updated: November 27, 2023 10:55 IST

San Francisco, Nov 27 Threat actors are delivering Atomic Stealer malware, also known as AMOS, to Mac users ...

Open in App

San Francisco, Nov 27 Threat actors are delivering Atomic Stealer malware, also known as AMOS, to Mac users via a fake browser update chain tracked as "ClearFake", a new report has found.

According to the cybersecurity company Malwarebytes, ClearFake is a newer malware campaign that leverages compromised websites to distribute fake browser updates.

"With a growing list of compromised sites at their disposal, the threat actors are able to reach out to a wider audience, stealing credentials and files of interest that can be monetised immediately or repurposed for additional attacks," the researchers said.

On November 17, security researcher Ankit Anubhav observed that ClearFake was dispersed to Mac users as well with a corresponding payload.

The ClearFake campaign began in July of this year, with the goal of targeting Windows users with bogus Chrome update prompts that appear on compromised sites via JavaScript injections.

According to the report, these attacks utilise a Safari update bait along with the standard Chrome overlay.

"The payload is made for Mac users, a DMG file purporting to be a Safari or Chrome update. Victims are instructed on how to open the file which immediately runs commands after prompting for the administrative password," according to the researchers.

In a file accessed by the researchers, they looked at the strings from the malicious application and saw those commands, which include password and file-grabbing capabilities.

In the same file, they found the malware’s command and control server where the stolen data was sent to.

"Because ClearFake has become one of the main social engineering campaigns recently, Mac users should pay particular attention to it. We recommend leveraging web protection tools to block the malicious infrastructure associated with this threat actor," the researchers suggested.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

EntertainmentMilind Soman says OTT platforms are giving 90s actors a new lease of opportunities

InternationalJapan PM Takaichi's Cabinet approval rating falls to 67.5 per cent amid Taiwan remarks

BusinessSimta Astrix Opens its New Experience Centre in Hyderabad, Showcasing the Best in Windows, Doors, and Interiors

LifestyleChristmas 2025 Special Cake Recipe: How to Make a Delicious Chocolate Cake at Home

InternationalFacts back Hasina's claim of law-and-order collapse under Yunus government: former Indian diplomat Mahesh Sachdev

International Realted Stories

InternationalBangladesh minorities protest lynching of Hindu man in Mymensingh, demand justice and security

InternationalIndia-New Zealand FTA: PM Modi, Luxon aim to double bilateral trade over 5 years

InternationalUS pursues sanctioned oil tanker near Venezuela after vessel refuses to stop

InternationalBangladeshi community, journalists in London condemn attacks on media outlets back home

International'Nobel Peace Prize is symbol of justice, not silence': Calls grow for action against Yunus amid B'desh violence