Atomic Stealer malware spread to Mac users via fake browser updates: Report

by IANS |

San Francisco, Nov 27 (IANS) Threat actors are delivering Atomic Stealer malware, also known as AMOS, to Mac users via a fake browser update chain tracked as "ClearFake", a new report has found.


According to the cybersecurity company Malwarebytes, ClearFake is a newer malware campaign that leverages compromised websites to distribute fake browser updates.


"With a growing list of compromised sites at their disposal, the threat actors are able to reach out to a wider audience, stealing credentials and files of interest that can be monetised immediately or repurposed for additional attacks," the researchers said.


On November 17, security researcher Ankit Anubhav observed that ClearFake was dispersed to Mac users as well with a corresponding payload.


The ClearFake campaign began in July of this year, with the goal of targeting Windows users with bogus Chrome update prompts that appear on compromised sites via JavaScript injections.


According to the report, these attacks utilise a Safari update bait along with the standard Chrome overlay.


"The payload is made for Mac users, a DMG file purporting to be a Safari or Chrome update. Victims are instructed on how to open the file which immediately runs commands after prompting for the administrative password," according to the researchers.


In a file accessed by the researchers, they looked at the strings from the malicious application and saw those commands, which include password and file-grabbing capabilities.


In the same file, they found the malware’s command and control server where the stolen data was sent to.


"Because ClearFake has become one of the main social engineering campaigns recently, Mac users should pay particular attention to it. We recommend leveraging web protection tools to block the malicious infrastructure associated with this threat actor," the researchers suggested.

Latest News
Police assault case: Odisha CM meets Army officer, woman Mon, Sep 23, 2024, 05:01 PM
Turkey: One police officer killed in gunfire exchange in Istanbul Mon, Sep 23, 2024, 05:00 PM
Ola Electric's share nosedives further, analysts warn investors to remain cautious Mon, Sep 23, 2024, 04:56 PM
SAFF U17 C'ship: India plot to rotate players in clash against Maldives Mon, Sep 23, 2024, 04:36 PM
Nigerian national held in Bengaluru, drugs worth Rs 1.5 cr seized Mon, Sep 23, 2024, 04:34 PM
South Korea expected to pass a bill to increase length of parental leave Mon, Sep 23, 2024, 04:32 PM
Sensex closes at all-time high, Nifty above 25,900 for first time Mon, Sep 23, 2024, 04:31 PM
Four Bangladeshi infiltrators pushed back by security forces: Assam CM Mon, Sep 23, 2024, 04:30 PM
Archbishop hails India's diversity, lauds PM's concern for all, including minorities Mon, Sep 23, 2024, 04:30 PM
NZ women fined for slow over-rate against Australia in first T20I Mon, Sep 23, 2024, 04:27 PM
GCCs expand in India, revenue growth to be 1-2 pc higher than ISPs: Report Mon, Sep 23, 2024, 04:16 PM
Transformative steps taken for healthcare, pandemic preparedness in India: Nadda Mon, Sep 23, 2024, 04:12 PM
Recoveries from stressed operational thermal plants to improve by 9 pc in next fiscal : Report Mon, Sep 23, 2024, 04:11 PM
Archbishop Oswald Gracias participates in 'Ek Ped Maa Ke Naam' event Mon, Sep 23, 2024, 04:10 PM
Japan: Death toll rises to 7 as unprecedented rainfall batters Ishikawa Mon, Sep 23, 2024, 03:40 PM