216.73.216.6

AMOS Stealer delivered via Cursor AI agent session

· Published 25/04/2026 06:37 · Modified 27/04/2026 14:58

Export JSON

Essential information

Published
25/04/2026 06:37
Modified
27/04/2026 14:58
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
ai agent exploitation amos stealer applescript credential harvesting cryptocurrency theft cursor persistent implant social engineering
Tags
2026-04-25 ai agent exploitation amos stealer applescript credential harvesting cryptocurrency theft cursor persistent implant social engineering
Related entities
13 indicators, 13 observables, 20 techniques (mitre), 1 malware, 5 others

Description

On April 23, 2026, Field Effect MDR identified malware delivered through a novel technique exploiting AI agent sessions running Claude Code. The attack employed to manipulate operators into prompting the AI agent to download and execute malicious loaders. The heavily obfuscated scripts performed sandbox evasion checks, collected sensitive data including credentials, SSH keys, browser data, and cryptocurrency wallets, then exfiltrated compressed archives to remote servers within two minutes. The malware prompted users for local account credentials through fake macOS system dialogs, subsequently using elevated permissions to install persistent implants masquerading as legitimate system services. This delivery mechanism makes detection challenging as malicious commands blend with typical agentic coding behavior, representing an evolution in tactics beyond traditional SEO poisoning methods.

External references