https://cairoict.com/trade-visitor-registration/ https://cairoict.com/trade-visitor-registration/ https://cairoict.com/trade-visitor-registration/
الأربعاء, 16 سبتمبر, 2026
سياسة الخصوصية
من نجن
No Result
View All Result
  • آخر الأخبار
  • أمن إلكتروني
  • خدمات مالية
  • تقنيات ومنصات
  • ريادة أعمال
  • عالم الألعاب
  • مدن المستقبل
  • أحدث المنتجات
  • ترند
  • English
Techno fin
No Result
View All Result
  • آخر الأخبار
  • أمن إلكتروني
  • خدمات مالية
  • تقنيات ومنصات
  • ريادة أعمال
  • عالم الألعاب
  • مدن المستقبل
  • أحدث المنتجات
  • ترند
  • English

Mac Users at Risk: Malware Exploits ChatGPT and Google Ads to Steal Data

by تكنو فن
ديسمبر 16, 2025
Reading Time: 4 mins read
A A
Mac

Kaspersky Threat Research has identified a new malware campaign that uses paid Google search ads and shared conversations on the official ChatGPT website to trick Mac users into running a command that installs the AMOS (Atomic macOS Stealer) infostealer and a persistent backdoor on their devices. 

In the campaign, attackers buy sponsored search ads for queries such as “chatgpt atlas” and direct users to a page that appears to be an installation guide for “ChatGPT Atlas for macOS” hosted at chatgpt.com. In reality, the page is a shared ChatGPT conversation generated through prompt engineering and then sanitized so that only the step-by-step “installation” instructions remain. The guide instructs users to copy a single line of code, open Terminal on macOS, paste the command, and grant all requested permissions.

Kaspersky researchers analysis shows that the command downloads and executes a script from the external domain atlas-extension[.]com. The script repeatedly prompts the user for their system password and validates the password by attempting to run system commands. Once the correct password is supplied, the script downloads the AMOS infostealer, uses the stolen credentials to install it, and launches the malware. The infection flow represents a variation of the so-called ClickFix technique, in which users are persuaded to manually execute shell commands that retrieve and run code from remote servers.

After installation, AMOS collects data that can be monetized or reused in later intrusions. The malware targets passwords, cookies, and other information from popular browsers, data from cryptocurrency wallets such as Electrum, Coinomi, and Exodus, and information from applications including Telegram Desktop and OpenVPN Connect. It also searches for files with TXT, PDF, and DOCX extensions in the Desktop, Documents, and Downloads folders, as well as files stored by the Notes application, then exfiltrates this data to attacker-controlled infrastructure. In parallel, the attack installs a backdoor that is configured to start automatically on reboot, gives remote access to the compromised system, and duplicates much of AMOS’s data-collection logic.

RelatedPosts

Cairo Design Week 2026 to Host MENA’s First Cross-Border Design Collective

NetApp Reinforces Commitment to Egypt’s Digital Future Through CONNECT Cairo 2026

POPCORN Launches AI Platform for Arabic Video Ad Production

The campaign reflects a broader trend in which infostealers have become one of 2025’s fastest-growing threats, with attackers actively experimenting with AI-related themes, fake AI tools, and AI-generated content to increase the credibility of their lures. Recent waves have included fake AI browser sidebars and fraudulent clients for popular models; the Atlas-themed activity extends this pattern by abusing a legitimate AI platform’s built-in content-sharing feature.

“What makes this case effective is not a sophisticated exploit, but the way social engineering is wrapped in a familiar AI context,” said Vladimir Gursky, Malware Analyst at Kaspersky. “A sponsored link leads to a well-formatted page on a trusted domain, and the ‘installation guide’ is just a single Terminal command. For many users, that combination of trust and simplicity is enough to bypass their usual caution, yet the result is full compromise of the system and long-term access for the attacker.”

Kaspersky recommends that users:

  • Treat any unsolicited “guide” that asks them to run Terminal or PowerShell commands with caution, especially when it involves copying and pasting a one-line script from a website, document, or chat.
  • Close pages or delete messages that ask for such actions if the instructions are unclear, and seek advice from a knowledgeable source before proceeding.
  • Consider pasting any suspicious commands into a separate AI or security tool to understand what the code does before executing it.
  • Install and maintain reputable security software on all devices, including macOS and Linux systems, such as Kaspersky Premium, to detect and block infostealers and related payloads.

شارك هذا الموضوع

  • المشاركة على WhatsApp (فتح في نافذة جديدة) WhatsApp
  • المشاركة على Telegram (فتح في نافذة جديدة) Telegram
  • المزيد
  • تدوينة
  • Tweet

مرتبط

Tags: AI phishingAMOSbackdoor malwareChatGPT Atlascyber threats 2025cybersecuritydata theftGoogle Ads malwareinfostealerKaspersky Threat Researchmac securitymacOS malwareterminal command malware

Related Posts

Cairo Design Week
English

Cairo Design Week 2026 to Host MENA’s First Cross-Border Design Collective

يونيو 22, 2026
NetApp
English

NetApp Reinforces Commitment to Egypt’s Digital Future Through CONNECT Cairo 2026

يونيو 21, 2026
English

POPCORN Launches AI Platform for Arabic Video Ad Production

يونيو 11, 2026
يلا جروب Yalla Group
English

Yalla Group Expands Regional Gaming Presence Through Saudi Esports Partnership

يونيو 7, 2026
Load More

آخر الأخبار

أورنچ مصر وكيربوينت تدعمان رقمنة الصيدليات

أورنچ مصر وكيربوينت تدعمان رقمنة الصيدليات

سبتمبر 15, 2026
كاسبرسكي: دعم كبار السن تقنيًا ضرورة في مصر

كاسبرسكي: دعم كبار السن تقنيًا ضرورة في مصر

سبتمبر 15, 2026
Money20/20 Middle East ينطلق في الرياض

Money20/20 Middle East ينطلق في الرياض

سبتمبر 15, 2026
تمويلي تحصد درع المعاقين لأول مرة

تمويلي تحصد درع المعاقين لأول مرة

سبتمبر 15, 2026
سوق أبوظبي يعزز الأصول الرقمية

سوق أبوظبي يعزز الأصول الرقمية

سبتمبر 15, 2026
No Result
View All Result
contact us: info@techno-fin.com Dubai:0553028804 Cairo:01150009990

Follow Us

All rights reserved to www.techno-fin.com, UAE, Sheikh Zayed Road, City Tower 2, 18th floor, office 1801
No Result
View All Result
  • آخر الأخبار
  • أمن إلكتروني
  • خدمات مالية
  • تقنيات ومنصات
  • ريادة أعمال
  • عالم الألعاب
  • مدن المستقبل
  • أحدث المنتجات
  • ترند
  • English