ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 86.54.25.202:443.

Database Entry


IOC ID:1834774
IOC: 86.54.25.202:443
IOC Type :ip:port
Threat Type :botnet_cc
Malware: AMOS
Malware alias:Atomic macOS Stealer
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS210006 ASKZ
First seen:2026-06-21 13:05:18 UTC
Last seen:never
UUID:74274ae4-6d5e-11f1-9258-42010aa4000a
Reporter Anonymous
Reward 5 credits from ThreatFox
Tags:Amos AtomicStealer ClickFix Cthulhu macOS xxxblyat
Reference: https://chainabuse.com/report/50a2071b-4c3e-488b-bebb-4c260a9c9b11

Avatar
Anonymous
AMOS / Atomic macOS Stealer (a.k.a. Cthulhu). Victim macOS host beaconed here
~every 60s via LaunchDaemon com.xdivcmp.plist. Delivery: Telegram ClickFix
"Google Workspace certificate" lure -> /launcher script. Panel label "xxxblyat",
bot ID 57fe8704f0544d4f83b0fa812dc0228a. Confirmed first-hand, still live 2026-06-21.