INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Lazarus Group Deploys Python-Based Infostealer Builder
| 2026-09-28 10:51 HIGH LOW DATA BREACH MALWARE & BOTNETS STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
On 2026-09-28, a Python-based Malware-as-a-Service (MaaS) infostealer builder was discovered, enabling operators to generate customized Windows infostealers. The system comprises a builder component and an embedded payload using Nuitka or PyInstaller compilation to evade detection. This malware targets Chromium and Firefox browsers, extracting credentials, cookies, and credit card data while employing anti-analysis techniques such as debugger detection and timing evasion. Approximately [IOC HIDDEN • LOGIN REQUIRED] indicators of compromise were associated with this attack. The current status is unclear, but the malware's ability to generate customized infostealers poses a significant threat to affected users.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
6bfcdb••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
71781a••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
450400••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
608e70••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
la•••••.com
ge•••••.com
gr•••••.com
fe•••••.com
ou•••••.zip
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
161.35.•••.•••
188.166.•••.•••
9ffe0e••••••••••••••••••••••••••
429ed6••••••••••••••••••••••••••
610f0c••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
MIDDLE_EAST
MIDDLE_EAST
EUROPE
EUROPE
NORTH_AMERICA
NORTH_AMERICA
cryptocurrencycryptocurrency
manufacturingmanufacturing
Incident Timeline
April 2024
AMOS stealer, a Python-based malware-as-a-service infostealer targeting macOS systems, was advertised on Telegram in April 2024.
Click on any entity below to view its context and source!
infrastructure
Macos
Background
AMOS stealer is an information stealer targeting macOS systems that was
advertised on Telegram as early as April 2024
.
organisation
Telegram
Background
AMOS stealer is an information stealer targeting macOS systems that was
advertised on Telegram as early as April 2024
.
July 31, 2026
Threat actors used a Python-based MaaS (Managed Access Service) infostealer builder to infect targets, and the initial URLs of the infection revealed various stages of post-infection activity.
Aug. 5, 2026
Threat actors used AMOS stealer to infect macOS devices via a malicious page hosted on getmacouscloud[.]com.
Click on any entity below to view its context and source!
infrastructure
Macos
This article examines an AMOS stealer infection generated on Aug. 5, 2026, from an instructional page claiming to install a “macOS toolkit.”
Characteristics of the Infection
The domain hosting the malicious page claiming to have installation instructions for a macOS toolkit is
getmacouscloud[.]com
.
organisation
Characteristics of the Infection
The
This article examines an AMOS stealer infection generated on Aug. 5, 2026, from an instructional page claiming to install a “macOS toolkit.”
Characteristics of the Infection
The domain hosting the malicious page claiming to have installation instructions for a macOS toolkit is
getmacouscloud[.]com
.
early August 2026
Threat actors used a Python-based MaaS (Managed Access Service) infostealer builder, referred to as "The Stealer Factory," to target victims in early August 2026.
Click on any entity below to view its context and source!
organisation
Atomic
Conclusion
This article reviewed an Atomic stealer malware infection from early August 2026.
2026/09/28
Threat actors used a Python-based Malware-as-a-Service (MaaS) infostealer builder, known as AMOS stealer, to target vulnerable macOS hosts through malicious websites and ClickFix campaigns.
Click on any entity below to view its context and source!
infrastructure
Windows
A Python-based Malware-as-a-Service builder enables operators to generate customized Windows infostealer executables.
ClickFix campaigns inject a script into a viewer's clipboard to paste into a Run window for Windows systems or a Terminal window for macOS systems.
infrastructure
Macos
ClickFix campaigns inject a script into a viewer's clipboard to paste into a Run window for Windows systems or a Terminal window for macOS systems.
Atomic macOS (AMOS) Stealer Activity.
Executive Summary
This article reviews an Atomic macOS (AMOS) stealer malware infection generated in a lab environment.
AMOS stealer represents a noticeable portion of macOS stealer-based malware and is
considered a growing threat
.
These sites offer instructions to install software such as
a macOS toolkit
but then actually install malware like AMOS stealer.
A malicious website advertising a quick setup for “macOS toolkit.”
We copied text from the page and pasted it into a Terminal window on our macOS system as shown in Figure 2.
Of note, before the infection would proceed, the macOS host presented a prompt to enter the user's password as shown below in Figure 7.
Since the user account on this macOS host was an administrative account, it proceeded when we entered the user's password.
After running the initial malicious text in the Terminal window, the Terminal process requested the following permissions:
Access to control the macOS Finder application
Access to files in the user's Desktop folder
Access to files in the user's Documents folder
Access to control the macOS Notes application
AMOS stealer collected and temporarily saved information under the host's
/…
FileGrabber/filezilla/
Directory:
FileGrabber/gcloud/
File:
FileGrabber/zsh_history
File:
info
Directory:
Telegram Data/
File:
username
The infected macOS host was a clean installation with no additional added applications.
The resulting analysis includes behavior from the infected macOS host, malware samples, post-infection artifacts and traffic patterns that indicate the types of information collected by this malware.
Indicators of Compromise
We discovered the following five files during this AMOS stealer infection:
Initial Zsh script downloaded from a command run from the macOS Terminal window
SHA-256 hash:
…9fede6072e30e7416dd276668fa2a9
File size: 330,768 bytes
File location:
/tmp/helper
File type: Mach-O universal binary with two architectures: x86_64 and ARM64
Binary from AMOS stealer infection persistent on the infected macOS host
SHA-256 hash:
6bfcdb4920383375b7e519918df7eb4db751b974b5571a15ce66b82478012620
File size: 438,576 bytes
File location:
/Users/[username]/Library/
Application Support/.com.apple.accountsd/AccountsHelper
File type: Mach-O universal binary with two architectures: x86_64 and ARM64
Another binary from AMOS stealer infection persistent on the infected macOS host
SHA-256 hash:
4504006d1911057be42435d4625f03d83c4d0b7b6898d14beb9cdeba6cf667b9
File size: 568,368 bytes
File location:
/Users/[username]/Library/
…on Support/.com.apple.metadata.mds/mdworker_shared
File type: Mach-O universal binary with two architectures: x86_64 and ARM64
Malicious website with instructions that will infect a vulnerable macOS host:
hxxps[:]//getmacouscloud[.]com
URL for the initial download decoded from Base64 text provided by the malicious website:
hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5…
organisation
Run
ClickFix campaigns inject a script into a viewer's clipboard to paste into a Run window for Windows systems or a Terminal window for macOS systems.
organisation
Terminal
ClickFix campaigns inject a script into a viewer's clipboard to paste into a Run window for Windows systems or a Terminal window for macOS systems.
organisation
ClickFix
Malware that we've assessed as AMOS stealer has been distributed through
ClickFix campaigns
as well as through
malicious ads
.
organisation
PyInstaller
The system comprises a builder component and an embedded payload, using Nuitka or PyInstaller compilation to evade detection.
organisation
XOR
The builder features automatic dependency installation, webhook configuration with XOR and Base64 encoding, and multiple compilation backends.
organisation
Discord
It harvests Wi-Fi passwords, Discord tokens, and Roblox session cookies while employing anti-analysis techniques including debugger detection, VM process blacklisting, disk size checks, and timing evasion.
organisation
Palo Alto Networks Product Protections
Palo Alto Networks Product Protections
Palo Alto Networks customers are better protected from AMOS stealer and related threats through the following products and services:
If you think you may have been compromised or have an urgent matter, get in touch with the
Unit 42 Incident Response team
or call:
North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42)
UK: +44.20.3743.3660
E…
organisation
Palo Alto Networks
Palo Alto Networks Product Protections
Palo Alto Networks customers are better protected from AMOS stealer and related threats through the following products and services:
If you think you may have been compromised or have an urgent matter, get in touch with the
Unit 42 Incident Response team
or call:
North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42)
UK: +44.20.3743.3660
E…
organisation
Initial Zsh
Indicators of Compromise
We discovered the following five files during this AMOS stealer infection:
Initial Zsh script downloaded from a command run from the macOS Terminal window
SHA-256 hash:
organisation
the macOS Terminal
Indicators of Compromise
We discovered the following five files during this AMOS stealer infection:
Initial Zsh script downloaded from a command run from the macOS Terminal window
SHA-256 hash:
data_breach
438,576 bytes
…9fede6072e30e7416dd276668fa2a9
File size: 330,768 bytes
File location:
/tmp/helper
File type: Mach-O universal binary with two architectures: x86_64 and ARM64
Binary from AMOS stealer infection persistent on the infected macOS host
SHA-256 hash:
6bfcdb4920383375b7e519918df7eb4db751b974b5571a15ce66b82478012620
File size: 438,576 bytes
File location:
/Users/[username]/Library/
data_breach
568,368 bytes File location
Application Support/.com.apple.accountsd/AccountsHelper
File type: Mach-O universal binary with two architectures: x86_64 and ARM64
Another binary from AMOS stealer infection persistent on the infected macOS host
SHA-256 hash:
4504006d1911057be42435d4625f03d83c4d0b7b6898d14beb9cdeba6cf667b9
File size: 568,368 bytes
File location:
/Users/[username]/Library/
organisation
/Library/Application
The plist file at
/tmp/starter
contains text that hints at a newly created file in the user's
/Library/Application Support/.com.apple.accountsd/
directory named
.service
.
organisation
File
71781ad8adefb499aee9bcbe1a166e69ccc37a47066682f617d65c76d8cde88c
File size: 1,991 bytes
File type: Zsh script text executable, ASCII text
File location:
hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688
Payload (Zsh script) extracted from the initially downloaded Zsh script
SHA-256 hash:
7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3f…
data_breach
1,991 bytes File type
71781ad8adefb499aee9bcbe1a166e69ccc37a47066682f617d65c76d8cde88c
File size: 1,991 bytes
File type: Zsh script text executable, ASCII text
File location:
hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688
Payload (Zsh script) extracted from the initially downloaded Zsh script
SHA-256 hash:
7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ff…
data_breach
330,768 bytes File location
71781ad8adefb499aee9bcbe1a166e69ccc37a47066682f617d65c76d8cde88c
File size: 1,991 bytes
File type: Zsh script text executable, ASCII text
File location:
hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688
Payload (Zsh script) extracted from the initially downloaded Zsh script
SHA-256 hash:
7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ff…
data_breach
1,213 bytes
…fd787a50257f92142e99bd688
Payload (Zsh script) extracted from the initially downloaded Zsh script
SHA-256 hash:
7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ffd3d1c154d40d7ca3a
File size: 1,213 bytes
File type: Zsh script text executable, ASCII text, ASCII text, with very long lines (323)
Installer for AMOS stealer
SHA-256 hash:
a598fcdcd49247312861ff90c16cb4a5d49fede6072e3…
organisation
Additional Resources
…ed from Base64 text provided by the malicious website:
hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688
URLs from extracted from the payload returned from the initial download:
hxxps[:]//grove-89[.]com/api/metrics/run?event=pasted
hxxps[:]//ferncore13[.]com/2kqYRM0DCrnyJgoS4gVLl_FHJRRdTUhGCbjyuYwpZ6c/m1/update
Additional Resources
organisation
AMOS
While several sources have published articles analyzing AMOS stealer, the associated indicators constantly change.
organisation
CAPTCHA
The ClickFix technique generally uses a fake CAPTCHA or other type of verification page offering instructions to continue to the website a viewer intends to visit.
organisation
GZIP
Base64-encoded GZIP-compressed payload in the initial Zsh script.
organisation
Infection Traffic
Post
Infection Traffic
Post-infection traffic consisted mainly of HTTP POST requests to a command and control (C2) server at
161.35.146[.]120
.
organisation
Wireshark
Figure 9 shows traffic from the infection filtered in Wireshark.
organisation
IP
The associated domains, URLs and IP addresses frequently change for AMOS stealer activity.
organisation
Cyber Threat Alliance
+82.080.467.8774
Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members.
organisation
CTA
+82.080.467.8774
Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
A Python-based Malware-as-a-Service builder enables operators to generate customized Windows infostealer executables.
ClickFix campaigns inject a script into a viewer's clipboard to paste into a Run window for Windows systems or a Terminal window for macOS systems.
Metrics
infrastructure
Macos
Affected Product
Atomic macOS (AMOS) Stealer Activity.
Executive Summary
This article reviews an Atomic macOS (AMOS) stealer malware infection generated in a lab environment.
Background
AMOS stealer is an information stealer targeting macOS systems that was
advertised on Telegram as early as April 2024
.
AMOS stealer represents a noticeable portion of macOS stealer-based malware and is
considered a growing threat
.
These sites offer instructions to install software such as
a macOS toolkit
but then actually install malware like AMOS stealer.
This article examines an AMOS stealer infection generated on Aug. 5, 2026, from an instructional page claiming to install a “macOS toolkit.”
Characteristics of the Infection
The domain hosting the malicious page claiming to have installation instructions for a macOS toolkit is
getmacouscloud[.]com
.
A malicious website advertising a quick setup for “macOS toolkit.”
ClickFix campaigns inject a script into a viewer's clipboard to paste into a Run window for Windows systems or a Terminal window for macOS systems.
We copied text from the page and pasted it into a Terminal window on our macOS system as shown in Figure 2.
Of note, before the infection would proceed, the macOS host presented a prompt to enter the user's password as shown below in Figure 7.
Since the user account on this macOS host was an administrative account, it proceeded when we entered the user's password.
After running the initial malicious text in the Terminal window, the Terminal process requested the following permissions:
Access to control the macOS Finder application
Access to files in the user's Desktop folder
Access to files in the user's Documents folder
Access to control the macOS Notes application
AMOS stealer collected and temporarily saved information under the host's
/…
FileGrabber/filezilla/
Directory:
FileGrabber/gcloud/
File:
FileGrabber/zsh_history
File:
info
Directory:
Telegram Data/
File:
username
The infected macOS host was a clean installation with no additional added applications.
The resulting analysis includes behavior from the infected macOS host, malware samples, post-infection artifacts and traffic patterns that indicate the types of information collected by this malware.
Indicators of Compromise
We discovered the following five files during this AMOS stealer infection:
Initial Zsh script downloaded from a command run from the macOS Terminal window
SHA-256 hash:
…9fede6072e30e7416dd276668fa2a9
File size: 330,768 bytes
File location:
/tmp/helper
File type: Mach-O universal binary with two architectures: x86_64 and ARM64
Binary from AMOS stealer infection persistent on the infected macOS host
SHA-256 hash:
6bfcdb4920383375b7e519918df7eb4db751b974b5571a15ce66b82478012620
File size: 438,576 bytes
File location:
/Users/[username]/Library/
Application Support/.com.apple.accountsd/AccountsHelper
File type: Mach-O universal binary with two architectures: x86_64 and ARM64
Another binary from AMOS stealer infection persistent on the infected macOS host
SHA-256 hash:
4504006d1911057be42435d4625f03d83c4d0b7b6898d14beb9cdeba6cf667b9
File size: 568,368 bytes
File location:
/Users/[username]/Library/
…on Support/.com.apple.metadata.mds/mdworker_shared
File type: Mach-O universal binary with two architectures: x86_64 and ARM64
Malicious website with instructions that will infect a vulnerable macOS host:
hxxps[:]//getmacouscloud[.]com
URL for the initial download decoded from Base64 text provided by the malicious website:
hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5…
Metrics
data_breach
1,991
Bytes File Type
71781ad8adefb499aee9bcbe1a166e69ccc37a47066682f617d65c76d8cde88c
File size: 1,991 bytes
File type: Zsh script text executable, ASCII text
File location:
hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688
Payload (Zsh script) extracted from the initially downloaded Zsh script
SHA-256 hash:
7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ff…
Metrics
data_breach
1,213
Bytes
…fd787a50257f92142e99bd688
Payload (Zsh script) extracted from the initially downloaded Zsh script
SHA-256 hash:
7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ffd3d1c154d40d7ca3a
File size: 1,213 bytes
File type: Zsh script text executable, ASCII text, ASCII text, with very long lines (323)
Installer for AMOS stealer
SHA-256 hash:
a598fcdcd49247312861ff90c16cb4a5d49fede6072e3…
Metrics
data_breach
330,768
Bytes File Location
71781ad8adefb499aee9bcbe1a166e69ccc37a47066682f617d65c76d8cde88c
File size: 1,991 bytes
File type: Zsh script text executable, ASCII text
File location:
hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688
Payload (Zsh script) extracted from the initially downloaded Zsh script
SHA-256 hash:
7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ff…
Metrics
data_breach
438,576
Bytes
…9fede6072e30e7416dd276668fa2a9
File size: 330,768 bytes
File location:
/tmp/helper
File type: Mach-O universal binary with two architectures: x86_64 and ARM64
Binary from AMOS stealer infection persistent on the infected macOS host
SHA-256 hash:
6bfcdb4920383375b7e519918df7eb4db751b974b5571a15ce66b82478012620
File size: 438,576 bytes
File location:
/Users/[username]/Library/
Metrics
data_breach
568,368
Bytes File Location
Application Support/.com.apple.accountsd/AccountsHelper
File type: Mach-O universal binary with two architectures: x86_64 and ARM64
Another binary from AMOS stealer infection persistent on the infected macOS host
SHA-256 hash:
4504006d1911057be42435d4625f03d83c4d0b7b6898d14beb9cdeba6cf667b9
File size: 568,368 bytes
File location:
/Users/[username]/Library/
Intelligence Sources
Palo Alto
2026-09-16
Atomic macOS (AMOS) Stealer Activity
Palo Alto
AlienVault OTX
2026-09-28
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:13
Comprehensive Tactical Telemetry
Highly Correlated Entities
26x
organisation
Identified Entity
PyInstaller
entity
5x
target region
Target Country
United Kingdom
country
5x
timeline
Temporal Reference
July 31, 2026
date
3x
target region
Target Region
MIDDLE_EAST
region
2x
infrastructure
Affected Product
Windows
software
2x
tactic
MITRE ATT&CK Technique
T1059.006 - Python
technique
2x
general metric
+1
866
+1
2x
data breach
Bytes
1,213
bytes
2x
data breach
Bytes File Location
330,768
bytes file location
Contextual Telemetry
Context Block
5 METRICS
tactic
Cyber Operation Type
Exfiltration
tactic
general metric
Incident
42
incident
general metric
South Korea
50
south korea
data breach
Bytes File Type
1,991
bytes file type
general metric
Long Lines
323
long lines
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.