DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Tech News

Kaspersky uncovers macOS infostealer campaign abusing ChatGPT’s chat-sharing feature

DigitalCIO Bureau by DigitalCIO Bureau
December 18, 2025
in Tech News
0
Cybercrime AI experimentation in the dark web – new Kaspersky study
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Kaspersky Threat Research has identified a new malware campaign that uses paid Google search ads and shared conversations on the official ChatGPT website to trick Mac users into running a command that installs the AMOS (Atomic macOS Stealer) infostealer and a persistent backdoor on their devices.

In the campaign, attackers buy sponsored search ads for queries such as “chatgpt atlas” and direct users to a page that appears to be an installation guide for “ChatGPT Atlas for macOS” hosted at chatgpt.com. In reality, the page is a shared ChatGPT conversation generated through prompt engineering and then sanitized so that only the step-by-step “installation” instructions remain. The guide instructs users to copy a single line of code, open Terminal on macOS, paste the command, and grant all requested permissions.

Kaspersky researchers analysis shows that the command downloads and executes a script from the external domain atlas-extension[.]com. The script repeatedly prompts the user for their system password and validates the password by attempting to run system commands. Once the correct password is supplied, the script downloads the AMOS infostealer, uses the stolen credentials to install it, and launches the malware. The infection flow represents a variation of the so-called ClickFix technique, in which users are persuaded to manually execute shell commands that retrieve and run code from remote servers.

After installation, AMOS collects data that can be monetized or reused in later intrusions. The malware targets passwords, cookies, and other information from popular browsers, data from cryptocurrency wallets such as Electrum, Coinomi, and Exodus, and information from applications including Telegram Desktop and OpenVPN Connect. It also searches for files with TXT, PDF, and DOCX extensions in the Desktop, Documents, and Downloads folders, as well as files stored by the Notes application, then exfiltrates this data to attacker-controlled infrastructure. In parallel, the attack installs a backdoor that is configured to start automatically on reboot, gives remote access to the compromised system, and duplicates much of AMOS’s data-collection logic.

The campaign reflects a broader trend in which infostealers have become one of 2025’s fastest-growing threats, with attackers actively experimenting with AI-related themes, fake AI tools, and AI-generated content to increase the credibility of their lures. Recent waves have included fake AI browser sidebars and fraudulent clients for popular models; the Atlas-themed activity extends this pattern by abusing a legitimate AI platform’s built-in content-sharing feature.

“What makes this case effective is not a sophisticated exploit, but the way social engineering is wrapped in a familiar AI context,” said Vladimir Gursky, Malware Analyst at Kaspersky. “A sponsored link leads to a well-formatted page on a trusted domain, and the ‘installation guide’ is just a single Terminal command. For many users, that combination of trust and simplicity is enough to bypass their usual caution, yet the result is full compromise of the system and long-term access for the attacker.”

 

Tags: Kaspersky
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

Palo Alto Networks Launches Next-Gen Identity Security Platform – Idira

by DigitalCIO Bureau
May 15, 2026
0
Palo Alto Networks Launches Next-Gen Identity Security Platform –  Idira

Palo Alto Networks has introduced Idira, a next-generation identity security platform designed to discover, control and govern all identities across every human, machine and agentic identity. This launch...

Read moreDetails

Synack Analysis Report of 11,000+ Vulnerabilities Highlights Top Security Vulnerabilities Attackers Are Weaponizing

by DigitalCIO Bureau
May 15, 2026
0
Synack Analysis Report of 11,000+ Vulnerabilities Highlights Top Security Vulnerabilities Attackers Are Weaponizing

New data shows faster remediation times, but rising high-severity flaws and expanding attack surfaces keep pressure on security teams Cybersecurity teams are getting faster at fixing critical vulnerabilities—but...

Read moreDetails

AI Poised to Add $500 Billion to India’s Economy by 2030, Finds IBM–IndiaAI Study

by DigitalCIO Bureau
May 14, 2026
0
AI Poised to Add $500 Billion to India’s Economy by 2030, Finds IBM–IndiaAI Study

India’s artificial intelligence push could add more than $500 billion to the country’s economy by 2030, as enterprises shift from pilots to large-scale deployment of AI systems, a...

Read moreDetails

Honda Sets Up Digital Services Hub in Bengaluru to Power Its Next-Gen Mobility Play in India

by DigitalCIO Bureau
May 14, 2026
0
Honda Sets Up Digital Services Hub in Bengaluru to Power Its Next-Gen Mobility Play in India

Honda has created a new India-based subsidiary, Honda Digital Innovation India Private Ltd. (HDII), to become the company’s nerve center for digital services and data-driven mobility in one...

Read moreDetails

Tech Mahindra, Cisco roll out ‘Cyber Resilience Fabric’ to strengthen enterprise threat detection

by DigitalCIO Bureau
May 13, 2026
0
Tech Mahindra, Cisco roll out ‘Cyber Resilience Fabric’ to strengthen enterprise threat detection

New joint platform blends Splunk, AI-driven risk scoring, and unified visibility to help large organizations move from alert overload to risk-based security decisions Tech Mahindra has teamed up...

Read moreDetails
Next Post
Protectt.ai Appoints Nitin Talwar as Head of Global Delivery and Solution Engineering

Protectt.ai Appoints Nitin Talwar as Head of Global Delivery and Solution Engineering

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Tata Elxsi Collaborates With Qualcomm

Tata Elxsi Collaborates With Qualcomm

January 6, 2025
Gartner: Adoption of GenAI To Collapse Cybersecurity Skills Gap

WatchGuard Introduces FireCloud Total Access

September 29, 2025
IDC: Ethernet Switch Market Decreased 7.9%

IDC: Ethernet Switch Market Decreased 7.9%

January 2, 2025

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Accenture Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Digital Transformation E-books Fortinet Gartner Generative AI Google Cloud HCLTech IBM Infographics Infosys Internet of Things (IoT) Kaspersky NTT DATA NVIDIA Palo Alto Networks Panel Discussion Qlik Salesforce ServiceNow Sophos Tata Consultancy Services TCS Tenable Trend Micro Veeam Veeam Software Vertiv Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?