making it one of the most prevalent and dangerous social engineering schemes.
On Nov 17, security researcher Ankit Anubhav observed that ClearFake was distributed to Mac users as well with a corresponding payload:
https://infosec.exchange/@ankit_anubhav/111425827558836814
Atomic Stealer, also known as AMOS, is a popular stealer for Mac OS. Back in September, malwarebytes described how malicious ads were tricking victims into downloading this piece of malware under the disguise of a popular application
ClearFake has become one of the main social engineering campaigns recently, Mac users should pay particular attention to it.
---- Malwarebytes
The Safari template mimics the official Apple website and is available in different languages:
Since Google Chrome is also popular on Macs, there is a template for it which closely resembles the one used for Windows users:
Fake browser updates have been a common theme for Windows users for years, and yet up until now the threat actors didn’t expand onto MacOS in a consistent way.
#MacOS