{"type":"bundle","id":"bundle--d49a5682-efd7-4630-810f-f1d4aeff6ff2","objects":[{"type":"identity","spec_version":"2.1","id":"identity--299678e4-02c7-41d1-92a6-86d8b1b322c5","created":"2026-09-16T11:11:53.795Z","modified":"2026-09-16T11:11:53.795Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--69effc6a-0ba5-4f01-9385-7475d61694de","created":"2026-09-16T10:00:06.000Z","modified":"2026-09-16T11:11:53.795Z","created_by_ref":"identity--299678e4-02c7-41d1-92a6-86d8b1b322c5","name":"url: https://ferncore13[","description":"Seen in \"Atomic macOS (AMOS) Stealer Activity\" (Palo Alto Unit 42). Context: e command in Figure 2 retrieved a Z-shell (Zsh) script from hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50","pattern":"[url:value = 'https://ferncore13[']","pattern_type":"stix","valid_from":"2026-09-16T10:00:06.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6267ba8e-5efd-481c-9ec5-5ba18264d06b","created":"2026-09-16T10:00:06.000Z","modified":"2026-09-16T11:11:53.795Z","created_by_ref":"identity--299678e4-02c7-41d1-92a6-86d8b1b322c5","name":"url: https://getmacouscloud[","description":"Seen in \"Atomic macOS (AMOS) Stealer Activity\" (Palo Alto Unit 42). Context: with instructions that will infect a vulnerable macOS host: hxxps[:]//getmacouscloud[.]com URL for the initial download decoded from Base64 tex","pattern":"[url:value = 'https://getmacouscloud[']","pattern_type":"stix","valid_from":"2026-09-16T10:00:06.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b79a2e07-fbd9-40b9-bbe8-e22660860cac","created":"2026-09-16T10:00:06.000Z","modified":"2026-09-16T11:11:53.795Z","created_by_ref":"identity--299678e4-02c7-41d1-92a6-86d8b1b322c5","name":"url: https://grove-89[","description":"Seen in \"Atomic macOS (AMOS) Stealer Activity\" (Palo Alto Unit 42). Context: racted from the payload returned from the initial download: hxxps[:]//grove-89[.]com/api/metrics/run?event=pasted hxxps[:]//ferncore13[.]","pattern":"[url:value = 'https://grove-89[']","pattern_type":"stix","valid_from":"2026-09-16T10:00:06.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--72bb2067-2b82-4681-a471-70d3ea456bfe","created":"2026-09-15T13:04:34.000Z","modified":"2026-09-16T11:11:53.795Z","created_by_ref":"identity--299678e4-02c7-41d1-92a6-86d8b1b322c5","name":"url: http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF","description":"Seen in \"Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters\" (GBHackers). Context: [.]com domain, the message embedded an IPv6-mapped address: hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 . That notation represents IPv4 address 103[.]193","pattern":"[url:value = 'http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF']","pattern_type":"stix","valid_from":"2026-09-15T13:04:34.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/trusted-email-abuse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f7642d4a-79ae-4863-9668-7f037c6fd07e","created":"2026-09-15T12:02:50.000Z","modified":"2026-09-16T11:11:53.795Z","created_by_ref":"identity--299678e4-02c7-41d1-92a6-86d8b1b322c5","name":"url: http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF","description":"Seen in \"New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools\" (Cyber Security News). Context: nder domain used in the Romanian banking phishing email URL hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 IPv6-mapped IP-literal URL embedded in the bankin","pattern":"[url:value = 'http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF']","pattern_type":"stix","valid_from":"2026-09-15T12:02:50.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-phishing-attacks/"}]}]}