{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/x-social-media/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["social-engineering","malware","stealer","remote-access-trojan","x-social-media"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eA social engineering campaign, identified by the Huntress SOC, targets users through X (formerly Twitter) direct messages. Attackers lure victims into interacting with a malicious Google Doc, which utilizes a sidebar mechanism to facilitate the delivery of secondary payloads. The campaign exhibits platform-aware capabilities, distinguishing between macOS and Windows operating systems to deliver distinct malware. Windows-based targets receive an installer for NetSupport Manager, a legitimate remote access tool repurposed for malicious activity. Simultaneously, macOS users are targeted with Atomic macOS Stealer (AMOS), an information stealer designed to extract browser data, credentials, and cryptocurrency wallet information. This campaign highlights the use of legitimate collaborative platforms to bypass perimeter defenses and social engineering to drive user interaction.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker sends a direct message via X containing a link to a Google Doc.\u003c/li\u003e\n\u003cli\u003eVictim accesses the Google Doc, which features a malicious sidebar element.\u003c/li\u003e\n\u003cli\u003eVictim clicks an embedded link or interacts with the document, triggering an external redirection.\u003c/li\u003e\n\u003cli\u003eThe delivery platform performs an operating system check via browser user-agent headers.\u003c/li\u003e\n\u003cli\u003eWindows targets are prompted to download and execute an installer containing NetSupport Manager.\u003c/li\u003e\n\u003cli\u003emacOS targets are served a malicious payload that triggers the execution of Atomic macOS Stealer (AMOS).\u003c/li\u003e\n\u003cli\u003eNetSupport Manager establishes C2 communication to grant the attacker remote control.\u003c/li\u003e\n\u003cli\u003eAMOS exfiltrates sensitive data, including local browser files and credentials, to attacker infrastructure.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign facilitates unauthorized remote access to Windows systems and comprehensive credential and data exfiltration from macOS systems. Victims face risks ranging from long-term persistence and system compromise to the theft of financial assets and private keys stored on infected machines.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDeploy endpoint detection mechanisms capable of identifying the execution of remote access tools and unauthorized credential access. Audit organizational policies regarding the use of external Google Docs shared via unsolicited direct messages. Prioritize the investigation of suspicious network connections associated with remote support software if not explicitly permitted by IT policy.\u003c/p\u003e\n","date_modified":"2026-09-11T18:53:34Z","date_published":"2026-09-11T18:53:34Z","id":"https://feed.craftedsignal.io/briefs/2026-09-google-doc-malware/","summary":"A social engineering campaign delivered via X direct messages leverages a Google Doc sidebar to deliver platform-specific malware, deploying NetSupport Manager on Windows and Atomic macOS Stealer (AMOS) on macOS.","title":"Cross-Platform Malware Campaign via Malicious Google Doc Sidebar","url":"https://feed.craftedsignal.io/briefs/2026-09-google-doc-malware/"}],"language":"en","title":"CraftedSignal Threat Feed - X-Social-Media","version":"https://jsonfeed.org/version/1.1"}