PULSE NAME
AMOS Stealer delivered via Cursor AI agent session
WHITE AlienVault 2026-04-25 Modified: 2026-04-27
17
IOCs
MEDIUM VOLUME
On April 23, 2026, Field Effect MDR identified AMOS Stealer malware delivered through a novel technique exploiting Cursor AI agent sessions running Claude Code. The attack employed social engineering to manipulate operators into prompting the AI agent to download and execute malicious AppleScript loaders. The heavily obfuscated scripts performed sandbox evasion checks, collected sensitive data including credentials, SSH keys, browser data, and cryptocurrency wallets, then exfiltrated compressed archives to remote servers within two minutes. The malware prompted users for local account credentials through fake macOS system dialogs, subsequently using elevated permissions to install persistent implants masquerading as legitimate system services. This delivery mechanism makes detection challenging as malicious commands blend with typical agentic coding behavior, representing an evolution in AMOS Stealer tactics beyond traditional SEO poisoning methods.
Indicators of Compromise (17)
All URL FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 domain
TYPEINDICATORDESCRIPTIONCREATED
URL https://arkypc.com/n8n/update 2026-04-25
FileHash-MD5 312147c0ae0d555a4d50fa627ff7d4f3 2026-04-25
FileHash-MD5 c54620dd3745fdeaff5ccc0db4132f11 2026-04-25
FileHash-SHA1 62360ea3b0030238b31dcae402f94c9c73474154 2026-04-25
FileHash-SHA1 df297141e4676b40c29739033468d58163280067 2026-04-25
FileHash-SHA256 8ef98fd781a6f1869657fc1acbc9b43a228a99e6fa5fe39c47cce8ab58066596 2026-04-25
FileHash-SHA256 c11bfc200c363ef76ad40b717b5a850daf699f6fa64a26a8ecf7848711bdbd9c 2026-04-25
IPv4 45.94.47.204 2026-04-25
IPv4 92.246.136.14 2026-04-25
URL https://arkypc.com/curl/ 2026-04-25
URL https://lakhov.com/contact 2026-04-25
URL https://ouilov.com/zxc/kito 2026-04-25
domain arkypc.com 2026-04-25
domain foto.gd 2026-04-25
domain lakhov.com 2026-04-25
domain mpasvw.com 2026-04-25
domain ouilov.com 2026-04-25