PULSE NAME
AMOS Stealer delivered via Cursor AI agent session
WHITE AlienVault 2026-04-25 Modified: 2026-04-27
17
IOCs
MEDIUM VOLUME
On April 23, 2026, Field Effect MDR identified AMOS Stealer malware delivered through a novel technique exploiting Cursor AI agent sessions running Claude Code. The attack employed social engineering to manipulate operators into prompting the AI agent to download and execute malicious AppleScript loaders. The heavily obfuscated scripts performed sandbox evasion checks, collected sensitive data including credentials, SSH keys, browser data, and cryptocurrency wallets, then exfiltrated compressed archives to remote servers within two minutes. The malware prompted users for local account credentials through fake macOS system dialogs, subsequently using elevated permissions to install persistent implants masquerading as legitimate system services. This delivery mechanism makes detection challenging as malicious commands blend with typical agentic coding behavior, representing an evolution in AMOS Stealer tactics beyond traditional SEO poisoning methods.
Indicators of Compromise (2 / 17 total)
All URL FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 62360ea3b0030238b31dcae402f94c9c73474154 2026-04-25
FileHash-SHA1 df297141e4676b40c29739033468d58163280067 2026-04-25