← Back to Pulse Feed
PULSE DETAIL
On April 23, 2026, Field Effect MDR identified AMOS Stealer malware delivered through a novel technique exploiting Cursor AI agent sessions running Claude Code. The attack employed social engineering to manipulate operators into prompting the AI agent to download and execute malicious AppleScript loaders. The heavily obfuscated scripts performed sandbox evasion checks, collected sensitive data including credentials, SSH keys, browser data, and cryptocurrency wallets, then exfiltrated compressed archives to remote servers within two minutes. The malware prompted users for local account credentials through fake macOS system dialogs, subsequently using elevated permissions to install persistent implants masquerading as legitimate system services. This delivery mechanism makes detection challenging as malicious commands blend with typical agentic coding behavior, representing an evolution in AMOS Stealer tactics beyond traditional SEO poisoning methods.
MITRE ATT&CK & Malware Families
Indicators of Compromise (17)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| URL | https://arkypc.com/n8n/update | — | 2026-04-25 | |
| FileHash-MD5 | 312147c0ae0d555a4d50fa627ff7d4f3 | — | 2026-04-25 | |
| FileHash-MD5 | c54620dd3745fdeaff5ccc0db4132f11 | — | 2026-04-25 | |
| FileHash-SHA1 | 62360ea3b0030238b31dcae402f94c9c73474154 | — | 2026-04-25 | |
| FileHash-SHA1 | df297141e4676b40c29739033468d58163280067 | — | 2026-04-25 | |
| FileHash-SHA256 | 8ef98fd781a6f1869657fc1acbc9b43a228a99e6fa5fe39c47cce8ab58066596 | — | 2026-04-25 | |
| FileHash-SHA256 | c11bfc200c363ef76ad40b717b5a850daf699f6fa64a26a8ecf7848711bdbd9c | — | 2026-04-25 | |
| IPv4 | 45.94.47.204 | — | 2026-04-25 | |
| IPv4 | 92.246.136.14 | — | 2026-04-25 | |
| URL | https://arkypc.com/curl/ | — | 2026-04-25 | |
| URL | https://lakhov.com/contact | — | 2026-04-25 | |
| URL | https://ouilov.com/zxc/kito | — | 2026-04-25 | |
| domain | arkypc.com | — | 2026-04-25 | |
| domain | foto.gd | — | 2026-04-25 | |
| domain | lakhov.com | — | 2026-04-25 | |
| domain | mpasvw.com | — | 2026-04-25 | |
| domain | ouilov.com | — | 2026-04-25 |