Tag
Atomic macOS (AMOS) Stealer Activity
1 rule 3 TTPs 4 IOCsAtomic macOS (AMOS) stealer uses deceptive 'toolkit' websites to trick users into executing terminal commands that deploy credential-harvesting malware and persistent Mach-O binaries.
Cross-Platform Malware Campaign via Malicious Google Doc Sidebar
2 TTPsA social engineering campaign delivered via X direct messages leverages a Google Doc sidebar to deliver platform-specific malware, deploying NetSupport Manager on Windows and Atomic macOS Stealer (AMOS) on macOS.
Braodo Stealer Screen Capture Activity
1 rule 1 TTPThe Braodo stealer malware captures victim desktop screenshots and stages them in temporary directories, facilitating subsequent data exfiltration.
MacSync Stealer Behavioral Hunting and Infrastructure Analysis
1 rule 3 TTPsMacSync Stealer is a macOS-based information stealer that evades detection through rapid domain rotation while maintaining consistent behavioral pivots in its payload retrieval, C2 communication, and chunked exfiltration patterns.
Windows Credential Access from Browser Password Store Detection
1 rule 3 TTPsThis brief describes a detection for suspicious activity on Windows systems where an uncommon or unauthorized process attempts to access browser user data profiles, a common behavior observed in Trojan Stealers like SnakeKeylogger to harvest sensitive browser information and credentials for exfiltration.
Suspicious Process Accessing Browser Password Store
2 rules 1 TTPDetection of non-browser processes accessing browser user data folders, a tactic used by malware such as Snake Keylogger to steal credentials and sensitive information.
Non-Chrome Process Accessing Chrome Login Data
2 rules 1 TTPThis analytic identifies non-Chrome processes accessing the Chrome user data file 'login data', an SQLite database containing sensitive information like saved passwords, potentially indicating credential theft attempts.
Non-Firefox Process Accessing Firefox Profile Directory
2 rules 1 TTPDetection of non-Firefox processes accessing the Firefox profile directory, potentially indicating malware attempting to steal user credentials and data.
Non-Discord Application Accessing Discord LevelDB Database
2 rules 1 TTPThis analytic detects non-Discord applications accessing the Discord LevelDB database by monitoring Windows Security Event logs (event code 4663), which may indicate attempts to steal Discord credentials or access sensitive user data, potentially compromising user profiles, messages, and other critical information.