Malware: SHub Stealer v2.0 Type: macOS AppleScript Infostealer Delivery: ClickFix (fake Apple security update) C2:
wewannaliveinpice[.]com
SHA256 (payload):8ef539340b4f8271ed783223b3e49b7b8099381c6439024e7407474698fe9f10
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| import "pe" | |
| rule INFO_V8_Javascript_Engine_Jul_11 : INFO JS COMPILER { | |
| meta: | |
| description = "This rule detects files compiled by the V8 Javascript engine." | |
| author = "@brkalbyrk7" | |
| date = "2024-07-10" | |
| sharing = "TLP:WHITE" | |
| tags = "info,javascript,compiler" | |
| reference = "https://github.com/v8/v8" |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Commands | |
| **All Available Commands:** | |
| `help` - Displays a list of commands. | |
| `ping` - Check system status and IP | |
| `screenshot` - Take a screenshot | |
| `download <filepath>` - Download a file C:/path/to/file.txt. | |
| `killself` - Terminates itself with aura. | |
| `delete <path>` - Deletes the specified file or folder. Ex: delete C:/path/to/file.txt | |
| `cmd <command>` - Runs a command in CMD and returns the result. | |
| `dir <optional path>` - Shows the current directory. This can be changed by putting a directory next to it. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # AMOS Stealer Domains - 16.12.2025 | |
| jmpbowl[.]xyz | |
| jmpbowl[.]space | |
| elfrodbloom[.]coupons | |
| argoflyleens[.]space | |
| kjvnsrux[.]frozendoome[.]com | |
| slabiflc[.]ergodown[.]com | |
| gmiyhkzh[.]ergodown[.]com | |
| gulgivmu[.]apple-pkgs[.]com | |
| filebreef[.]com |
hxxps://index.orbitstreamvault4[.]lat/c3/?c=AM6HwGmifAUAvYwCAElUOQASAAAAAAA-
hxxps://filealphaweave[.]com/c3/?c=ANIbyWn3bQUAvYwCAEZSOQAZAAAAAACr
hxxps://fileomegaform[.]com/c3/?c=ALL-x2lxgAUAvYwCAElOOQAZAAAAAACZ
hxxps://index.nebulasyncforge4[.]baby/c3/?c=ABYAxmmifAUAvYwCAENMOQAZAAAAAAAx
hxxps://upsreit[.]com/c3/?c=AL2bvGmifAUAvYwCAE1YOQAZAAAAAACs
MacSync ClickFix domains
filesolarpatch[.]com
filecybertrail[.]com
ultranodecluster1[.]homes
ultranodecluster2[.]homes
ultranodecluster3[.]homes
ultranodecluster4[.]homes
ultranodecluster5[.]homes
index[.]orbitstreamvault4[.]lat
Stealers observed in the DriveSurge campaign (Silent Push: ClickFix + fake update driveby attacks on thousands of compromised sites). Two stage macOS malware with dedicated arm64 (Apple Silicon) and x86_64 (Intel) builds, obfuscated bash loader → ~30MB Garble Obfuscated Go stealer. Steals 100+ crypto wallets, macOS Keychain, browser creds/cookies, SSH/GPG keys. Patches Atomic Wallet & Exodus Electron apps to intercept passwords. Shows fake Ledger Live / Trezor Suite "security update" dialogs to phish 24-word seed phrases. Persistence via LaunchAgent + ~/.persistenced.
http://89.208.97.111:8133/api/t
http://45.155.71.15:8133/api/t
http://213.165.42.172:8133/api/t