INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Lazarus Group Deploys Python-Based Infostealer Builder

| 2026-09-28 10:51 HIGH LOW DATA BREACH MALWARE & BOTNETS STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
On 2026-09-28, a Python-based Malware-as-a-Service (MaaS) infostealer builder was discovered, enabling operators to generate customized Windows infostealers. The system comprises a builder component and an embedded payload using Nuitka or PyInstaller compilation to evade detection. This malware targets Chromium and Firefox browsers, extracting credentials, cookies, and credit card data while employing anti-analysis techniques such as debugger detection and timing evasion. Approximately [IOC HIDDEN • LOGIN REQUIRED] indicators of compromise were associated with this attack. The current status is unclear, but the malware's ability to generate customized infostealers poses a significant threat to affected users.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

6bfcdb••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
71781a••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
450400••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
608e70••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
la•••••.com
ge•••••.com
gr•••••.com
fe•••••.com
ou•••••.zip
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
161.35.•••.•••
188.166.•••.•••
9ffe0e••••••••••••••••••••••••••
429ed6••••••••••••••••••••••••••
610f0c••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
MIDDLE_EAST MIDDLE_EAST EUROPE EUROPE NORTH_AMERICA NORTH_AMERICA cryptocurrencycryptocurrency manufacturingmanufacturing
Incident Timeline
‎April 2024
AMOS stealer, a Python-based malware-as-a-service infostealer targeting macOS systems, was advertised on Telegram in April 2024.
infrastructure Macos
organisation Telegram
‎July 31, 2026
Threat actors used a Python-based MaaS (Managed Access Service) infostealer builder to infect targets, and the initial URLs of the infection revealed various stages of post-infection activity.
‎Aug. 5, 2026
Threat actors used AMOS stealer to infect macOS devices via a malicious page hosted on getmacouscloud[.]com.
infrastructure Macos
organisation Characteristics of the Infection The
‎early August 2026
Threat actors used a Python-based MaaS (Managed Access Service) infostealer builder, referred to as "The Stealer Factory," to target victims in early August 2026.
organisation Atomic
‎2026/09/28
Threat actors used a Python-based Malware-as-a-Service (MaaS) infostealer builder, known as AMOS stealer, to target vulnerable macOS hosts through malicious websites and ClickFix campaigns.
infrastructure Windows
infrastructure Macos
organisation Run
organisation Terminal
organisation ClickFix
organisation PyInstaller
organisation XOR
organisation Discord
organisation Palo Alto Networks Product Protections
organisation Palo Alto Networks
organisation Initial Zsh
organisation the macOS Terminal
data_breach 438,576 bytes
data_breach 568,368 bytes File location
organisation /Library/Application
organisation File
data_breach 1,991 bytes File type
data_breach 330,768 bytes File location
data_breach 1,213 bytes
organisation Additional Resources
organisation AMOS
organisation CAPTCHA
organisation GZIP
organisation Infection Traffic Post
organisation Wireshark
organisation IP
organisation Cyber Threat Alliance
organisation CTA
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Macos
Affected Product
Metrics
data_breach
1,991
Bytes File Type
Metrics
data_breach
1,213
Bytes
Metrics
data_breach
330,768
Bytes File Location
Metrics
data_breach
438,576
Bytes
Metrics
data_breach
568,368
Bytes File Location
Intelligence Sources