Cyber Security

Beware of Fake Microsoft Teams That Deliver macOS Malware

Hackers often mimic popular tools like Microsoft Teams to exploit people’s trust and familiarity with these applications. 

This strategy increases the probability of users’ subsequent downloading and installation of this malicious software, consequently permitting attackers to access systems, steal critical information, and launch other attacks without being detected immediately. 

Cybersecurity researchers at MalwareBytes recently discovered fake Microsoft Teams that deliver macOS malware.

Are you from SOC/DFIR Teams? - Sign up for a free ANY.RUN account! to Analyse Advanced Malware Files

Fake macOS Malware

The Atomic Stealer malware, disguised as a Microsoft Teams ad, is the latest malvertising campaign aimed at Mac users. It comes just after the recent appearance of the Poseidon (OSX.RodStealer) threat, which used similar strategies.

Fake ad (Source – MalwareBytes)

It lasted for several days and involved several sophisticated filter methods to avoid detection.

Although the advertisement displays Microsoft[.]com, it does not concern Microsoft, and it comes from an advertiser based in Hong Kong who has many unconnected ads.

This indicates the continuing rivalry among MacOS stealers and their use of popular communication tools to spread malware.

Users are targeted by a crafty Microsoft Teams ad that has a complicated attack chain with user profiling, cloaking, and a decoy page. The victim is then tricked into downloading a specifically created malware that appears to be Teams.

The installation process mandates human intervention to get through Apple’s defenses. Atomic Stealer uses this breach to enter the file system and steal keychain passwords.

The data loss happens in one encoded POST request sent to the remote server without being noticed by the user.

Encoded POST request (Source – MalwareBytes)

Malwarebytes report states that threat actors’ distribution campaigns are becoming more intense, which increases the risks associated with downloading apps through search engines.

Similarly, users are exposed to malvertising in sponsored results and SEO poisoning on hacked sites.

Consequently, it is advisable to use browser protection tools to prevent advertisements and malicious websites from appearing, as this may prevent redirections to harmful installers even before any downloads happen.

IoCs (Indicators of Compromise)

Cloaking domain:-

  • voipfaqs[.]com

Decoy site:-

  • teamsbusiness[.]org

Download URL:-

  • locallyhyped[.]com/kurkum/script_66902619887998[.]92077775[.]PHP

Atomic Stealer payload:-

  • 7120703c25575607c396391964814c0bd10811db47957750e11b97b9f3c36b5d

Atomic Stealer C2:-

  • 147.45.43[.]136

“Is Your System Under Attack? Try Cynet XDR: Automated Detection & Response for Endpoints, Networks, & Users!”- Free Demo

Kaaviya

Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago