Atomic MacOS (AMOS) stealer infection https://isc.sans.edu/diary/33208
Brad
@malware-traffic-analysis.net
Sharing information on malicious network traffic and malware samples at https://www.malware-traffic-analysis.net/
2026-07-31 (Friday): #SmartApeSG #ClickFix campaign pushes unidentified #RAT malware. A #pcap of the infection traffic, the associated #malware files, and further info available at www.malware-traffic-analysis.net/2026/07/31/i...
2026-06-09 (Tuesday): Documented an Atomic macOS ( #AMOS ) Stealer infection in my lab. A #pcap of the traffic, the associated malware, and a list of indicators are available at www.malware-traffic-analysis.net/2026/06/09/i...
ISC Diary: Unidentified RAT pushes NetSupport RAT https://isc.sans.edu/diary/33034
ISC Diary: #ACRStealer from web page impersonating Claude https://isc.sans.edu/diary/33018
2026-05-11 (Monday) #Malvertizing: Another ad in Google search results leads to a page impersonating a Claude download but distributing #macOS #malware. A #pcap of the infection traffic, some of the indicators and associated files are available at www.malware-traffic-analysis.net/2026/05/11/i...
2026-05-08 (Friday): Fake Homebrew page on nycaihong[.]com for #macOS #malware Possibly distributing #MacSyncStealer using an initial loader from hxxp[:]//longbeachmartialarts[.]com/curl/116f3b0bd8053eead15479f4b04bd2d9bc050f282eceeec87fd7908458ad3abe
2026-05-08 (Friday): #macOS #ShubStealer infection #pcap, malware files, and a list of indicators available at malware-traffic-analysis.net/2026/05/08/i...
ISC Diary: Malicious ad for Homebrew leads to #MacSync #Stealer https://isc.sans.edu/diary/32942
2026-04-22: Malicious ad ( #Malvertizing ) for Claude leads to #ClickFix style page for #macOS #malware Details at www.malware-traffic-analysis.net/2026/04/22/i... I've read about this activity from other sources, but this is the infection I generated in my lab and finally got around to posting.
2026-04-23 (Thursday): #SmartApeSG campaign using #ClickFix instructions to push some sort of #RAT. Not sure what this #malware is yet, but it looks like a RAT. Details at www.malware-traffic-analysis.net/2026/04/23/i...
2026-04-16 (Thursday): #pcap and #malware samples from the #LummaStealer infection with #SectopRAT ( #ArechClient2 ) that I documented in an ISC diary at isc.sans.edu/diary/Lumma+...
ISC Diary: #LummaStealer infection with #SectopRAT (#ArechClient2) https://isc.sans.edu/diary/32904
2026-04-13 (Monday): #XLoader ( #Formbook ) infection. A #pcap of the traffic, along with the associated email and malware samples are available at malware-traffic-analysis.net/2026/index.h...
2026-04-06 (Monday): #ClickFix activity from the #SmartApeSG campaign. Not sure what malware was sent through the fake CAPTCHA page is this time, but it's not the usual. Indicators, a #pcap of the traffic, malware samples and other info available at malware-traffic-analysis.net/2026/04/06/i...
ISC Diary: #SmartApeSG campaign pushes #Remcos #RAT, #NetSupportRAT, #StealC and #SectopRAT (#ArechC https://isc.sans.edu/diary/32826
2026-03-23: #PhantomStealer malware sent as an email attachment. .js file sample from the attachment: bazaar.abuse.ch/sample/8606c... PowerShell script retrieved by the above .js file: bazaar.abuse.ch/sample/a0d72...
#CVE_2017_11882 in this day and age? Saw this or some similar very old exploit from an Excel file attached to a message sent to my blog email address. Sample available at bazaar.abuse.ch/sample/263b3... It's for a #Snake KeyLogger infection. Thanks to @jamesinthebox.bsky.social for identifying it!
ISC diary: #SmartApeSG campaign uses #ClickFix page to push #Remcos #RAT (#RemcosRAT) https://isc.sans.edu/diary/32796
February 2026 #TrafficAnalysisExercise You get a pcap, you find your kidnapped daughter--I mean, you find the infected Windows host! Join the fun at www.malware-traffic-analysis.net/2026/02/28/i...
2026-02-03 (Tuesday): #GuLoader for #AgentTesla style malware with FTP data exfiltration. A #pcap of the infection traffic, associated files, and a list of indicators are available at www.malware-traffic-analysis.net/2026/02/03/i...
Reposted with correct malware names: 2026-02-02 (Monday) #KongTuke #ClickFix activity leads to #MintsLoader and #GhostWeaver RAT Today's ClickFix uses the "finger" command, a tactic seen in previous ClickFix activity. Further details available at www.malware-traffic-analysis.net/2026/02/02/i...
2026-02-01 (Sunday): It's easy enough to find #LummaStealer malware samples. Just do a Google search for cracked versions of popular software and specify site:drive.google.com. Details on today's haul at github.com/malware-traf...
2026-01-31 (Friday): I've posted a new traffic analysis exercise. It's Lumma in the room-ah! Join the fun at www.malware-traffic-analysis.net/2026/01/31/i... I mean, this guy looks like he's having fun.
2026-01-22 (Thursday): #RemcosRAT infection persistent on an infected Windows host. This was caused by #ClickFix instructions from #SmartApeSG through a fake CAPTCHA page. Details of this #Remcos #RAT infection are available at www.malware-traffic-analysis.net/2026/01/06/i...
2026-01-19 (Monday): Catching up on two infections in my lab from last week, and I added an entry with a #pcap of scans and probes and web traffic hitting my web server. Feel free to check out my latest posts at www.malware-traffic-analysis.net/2026/index.h... Or not. I'm not the boss of you.
ISC Diary: Infection repeatedly adds scheduled tasks & increases traffic to same C2 domain https://isc.sans.edu/diary/32628
2026-01-10 (Saturday): Ten days of scans, probes, and web traffic hitting my web server. A #pcap of the traffic is available at www.malware-traffic-analysis.net/2026/01/10/i...
2026-01-09 (Friday): #VIPRecovery infection from an email attachment. A #pcap of the infection traffic, associated files, and more information are available at www.malware-traffic-analysis.net/2026/01/09/i...
2026-01-08 (Thursday): Got a full infection from #KongTuke campaign #ClickFix activity today. Traffic from the infection in two #pcap files, the associated malware, artifacts, and further information is available at www.malware-traffic-analysis.net/2026/01/08/i...