Part of a story covered by 4 sources: “Cisco Talos Exposes UAT-10820 ClickFix Campaign Using Fake Google CAPTCHA, WebDAV and BNB Smart Chain to Deliver Amatera and ZigCryptoStealers” — merged summary and timeline →
Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware
AI summary · glm-5.3-flash
Huntress analysts trace one X direct message into separate Mac and Windows malware chains delivering AMOS infostealer and NetSupport Manager RAT.
Huntress SOC analysts dissected a malware campaign distributed via an X direct message styled as a Google Docs sidebar. macOS users were routed to the AMOS infostealer, while Windows users received NetSupport Manager remote access malware. The write-up details how a single message branched into two distinct delivery paths per operating system.
- Single X DM delivered different payloads per operating system
- Mac users received the AMOS infostealer
- Windows users received NetSupport Manager RAT
- Huntress SOC published a full delivery-path breakdown
Full article
A single X DM split into two malware chains: AMOS stealer on Mac, NetSupport Manager on Windows, see the Huntress SOC analyst breakdown.
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at huntress.com.