216.73.217.22

A SOC Team’s Guide to Detecting macOS Atomic Stealers

· Published 13/09/2024 08:59 · Modified 13/09/2024 09:26

Export JSON

Essential information

Published
13/09/2024 08:59
Modified
13/09/2024 09:26
Tags
2024-09-13 amos atomic banshee crimeware cthulu infostealer macos malware obfuscation poseidon rodrigostealer
Related entities
3 observables, 1 intrusion sets (apt), 20 techniques (mitre), 5 malware

Description

This article provides an analysis of the Atomic family, which has been targeting users throughout 2024. It discusses the various evolving variants, such as Amos, , , , and , developed and distributed by competing threat actor groups. The 's distribution methods have expanded to spoof enterprise applications, making it more concerning. The article examines the characteristics, techniques, and behaviors of different variants to aid in detection and triage.

External references