🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://delta-canvas.com/zxc/kito.

Database Entry


IOC ID:1932263
IOC: https://delta-canvas.com/zxc/kito
IOC Type :url
Threat Type :payload_delivery
Malware: AMOS
Malware alias:Atomic macOS Stealer
Confidence Level : Confidence level is high (90%)
Is compromised? : False
ASN:AS13335 CLOUDFLARENET
Country:- US
First seen:2026-09-24 12:56:36 UTC
Last seen:never
UUID:cce1690a-b816-11f1-abee-42010aa4000a
Reporter c4ffeine
Reward 5 credits from ThreatFox
Tags:Amos cc2 ClickFix Foxveil macOS
Reference: https://www.virustotal.com/gui/file/b9aba591f9ea7faccc80e23b5821e14a0fd208979737019c6d61c86e4bb813e9

Avatar
c4ffeine
Foxveil second-stage modules fetched by the AMOS AppleScript payload of the cc2 and DANTE builds since cc2 build 28: /zxc/kito = WebSocket remote-shell PTY bot (ThreatFox 1928014), /zxc/mdw = multi-chain crypto clipper (ThreatFox 1928015). UA-gated: genuine Mach-O to curl/8.7.1, Cloudflare 520 to a browser User-Agent, so crawlers see nothing; bodies fetched via Tor 2026-09-22. URLhaus 3921349 (kito) and 3921347 (mdw). Sample: https://www.virustotal.com/gui/file/b9aba591f9ea7faccc80e23b5821e14a0fd208979737019c6d61c86e4bb813e9