Tag
medium
advisory
Credential Access via Chromium Remote Debugging
1 rule 1 TTPAdversaries can exploit Chromium-based browser remote debugging features to extract authentication cookies and hijack active web sessions.
Chrome +1
credential-access
information-stealer
browser-security
1r
1t
high
advisory
Atomic macOS (AMOS) Stealer Activity
1 rule 3 TTPs 4 IOCsAtomic macOS (AMOS) stealer uses deceptive 'toolkit' websites to trick users into executing terminal commands that deploy credential-harvesting malware and persistent Mach-O binaries.
macos
malware
stealer
information-stealer
1r
3t
4i
high
advisory
MacSync Stealer Behavioral Hunting and Infrastructure Analysis
1 rule 3 TTPsMacSync Stealer is a macOS-based information stealer that evades detection through rapid domain rotation while maintaining consistent behavioral pivots in its payload retrieval, C2 communication, and chunked exfiltration patterns.
macos
stealer
information-stealer
1r
3t