Exploiting Clickfix: AMOS macOS Stealer Evades Security to Deploy Malicious Code
An Atomic macOS Stealer (AMOS) variant campaign has been identified, indicating advanced multi-platform social engineering attacks.
An Atomic macOS Stealer (AMOS) variant campaign has been identified, indicating advanced multi-platform social engineering attacks.
This campaign exploits typo-squatted domains impersonating Spectrum, a U.S.-based telecommunications provider, to deliver payloads tailored to the victim's operating system.
macOS users are targeted with a malicious shell script designed to extract system passwords and deploy an AMOS variant for further exploitation.
The attack involves luring victims to typo-squatted domains such as panel-spectrum[.]net and spectrum-ticket[.]net, where they are prompted to click on an “Alternative Verification” option. This action copies a malicious command to the clipboard, providing platform-specific instructions.
Non-macOS user agents receive a PowerShell command from a command-and-control (C2) server, while macOS users are given a Bash command that downloads a script containing a harmful attack chain.
The script harvests the victim’s password, validates it, and stores it. A malicious binary is downloaded, bypassing macOS security using the stolen password, and executes the AMOS variant.
This method, which leverages legitimate tools, reduces detection by traditional security solutions, allowing attackers to steal credentials and potentially facilitate further intrusions.
This AMOS campaign poses significant risks, especially for corporate users whose credentials could grant access to sensitive resources. The use of native macOS commands to bypass security highlights the difficulty of detecting such threats.
An Atomic macOS Stealer (AMOS) variant campaign has been identified, indicating advanced multi-platform social engineering attacks.
Organizations should enhance user awareness to recognize deceptive tactics, enforce system integrity protections, and restrict unsigned script execution. Threat hunting for unusual activities and known AMOS indicators can help identify compromises early.
Indicator Type Value Use
Domain panel-spectrum[.]net Clickfix Delivery
Domain spectrum-ticket[.]net Clickfix Delivery
Domain cf-verifi.pages[.]dev Command and Control
Domain applemacios[.]com Command and Control
MD5 Hash eaedee8fc9fe336bcde021bf243e332a AMOS Variant
URL https://cf-verifi.pages[.]dev/i.txt Contacted URLs
URL https://applemacios[.]com/getrur/install.sh Contacted URLs
URL https://applemacios[.]com/getrur/update Contacted URLs
Domain rugmel[.]cat Clickfix Indicator of Future Attack
Based on reporting by GBHackers.
