Shamos macOS Infostealer: Malvertising Lures, BYOD Gaps, and Sector Expansion
Shamos, a new Atomic macOS Stealer (AMOS) variant attributed to COOKIE SPIDER, is targeting U.S. tech and education sectors via malvertising and fake support sites.
Shamos, a new Atomic macOS Stealer (AMOS) variant attributed to COOKIE SPIDER, is targeting U.S. tech and education sectors via malvertising and fake support sites.
The user may start the incident. OAuth apps, tokens, and integrations can turn it into quiet, scalable data theft.
Zero-click Zimbra access, exposed PLC tampering, and Teams-to-ransomware chains compress the defender’s window. Prioritize server logs, controller-change evidence, and external admin-surface discovery.
We put a 30% chance on two public FCEB cases proving post-deadline edge exploitation by year-end.
We put a 45% chance on a public case proving that stolen edge-appliance access survived remediation and enabled a later intrusion.