Theregister
Fake Codex Installer Delivers Suspected AMOS Infostealer via Google Sites
Article Content
A malicious campaign has emerged, using fake Codex installation pages to deliver malware targeting macOS users. The attackers utilize Google Sites to host a fraudulent download portal that appears legitimate, tricking users into executing a command that initiates a multi-stage malware infection. The command, disguised as a legitimate installation process, retrieves a shell script that ultimately downloads a Mach-O binary suspected to be the Atomic macOS Stealer (AMOS). Cato Networks identified multiple infrastructure sets and obfuscation techniques used in this campaign, including path-aware content serving to evade detection. The malware is designed to run on both Intel and Apple Silicon Macs, with significant similarities to known AMOS campaigns. The campaign is ongoing, with researchers advising caution to users searching for AI coding tools.
Key Points: • Fake Codex download pages are used to deliver malware to macOS users. • The attack employs ClickFix techniques to obfuscate malicious content within trusted domains. • The final payload is suspected to be the Atomic macOS Stealer (AMOS), targeting both Intel and Apple Silicon Macs.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.