ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain macos.certificates.ltd.

Database Entry


IOC ID:1834775
IOC: macos.certificates.ltd
IOC Type :domain
Threat Type :payload_delivery
Malware: AMOS
Malware alias:Atomic macOS Stealer
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS13335 CLOUDFLARENET
Country:- US
First seen:2026-06-21 13:05:18 UTC
Last seen:2026-06-21 10:50:03 UTC
UUID:f557a5cf-6d5e-11f1-9258-42010aa4000a
Reporter Anonymous
Reward 5 credits from ThreatFox

Avatar
Anonymous
AMOS / Atomic macOS Stealer (a.k.a. Cthulhu). Victim macOS host beaconed here
~every 60s via LaunchDaemon com.xdivcmp.plist. Delivery: Telegram ClickFix
"Google Workspace certificate" lure -> /launcher script. Panel label "xxxblyat",
bot ID 57fe8704f0544d4f83b0fa812dc0228a. Confirmed first-hand, still live 2026-06-21.