Hackers exploited a trusted Reddit identity to turn legitimate advertisements into a malware delivery system This article explores hackers exploited trusted. .

Indicators of Compromise (IoCs): - Type Indicator Description - IP address 45.94.47[. ]204:80: AMOS helper enrollment, task polling, and acknowledgement server - IP address 77.91.65[. ]13:443: Amatera direct-to-IP TLS command-and-control server using facebook[.

]com SNI - IP address 165.22.199[. ]85: September macOS telemetry and /contact data exfiltration - IP address 164.90.161[. ]147:80: September macOS post-execution HTTP contact - IP address 92.246.136[. ]14: AMOS helper fallback /contact exfiltration - IP address 62.60.226[.

]69: Shared Nova and macOS-tool cluster provisioning infrastructure - IP address 176.53.159[. ]66: Shared delivery infrastructure associated with TLS and Windows executable activity - IP address 172.236.51[. ]169: Origin observed for storageprofiler[. ]com gated lure - IP address 138.124.93[.

]32: AMOS helper /contact exfiltration - IP address 168.100.9[. ]122: AMOS helper /contact exfiltration - IP address 199.217.98[. ]33: AMOS helper /contact exfiltration - IP address 38.244.158[. ]103: AMOS helper /contact exfiltration - IP address 38.244.158[.

]56: AMOS helper /contact exfiltration - Domain filequanticore[. ]com; filesiriuscore[. ]com; alfredaps[. ]com; hbomaxx[.

]us; hbomax-macos[. ]com; bright-links[. ]com; codex-notes[. ]com; storageprofiler[.

]com; cladesktop[.]gitlab[. ]io; cli-desktop[. ]com; cli-stack[. ]com; homebrwmac-hub[.

]com; clean-disk-guide[. ]com: Copied-command lure domains - Domain flutelikelurkerunsinewy[. ]com; camaligsalvatrefoils[. ]com: Click-tracking domains - Domain press29[.

]com; leaf68[. ]com; basequill9[. ]com; perchframe15[. ]com; canvas-35[.

]com; pine63[. ]com; trekmesh15[. ]com: macOS loader-delivery domains - Domain weaveridge7[. ]com; ember-bridge[.

]com; rudder-moss[. ]com; wuess[. ]com: September macOS telemetry and delivery domains - Domain houstongaragedoorinstallers[. ]com; pressureulcerlawyer[.

]com; lalandscapelighting[. ]com; aidevmaster[. ]com; pinescope11[. ]com; dogtrainersgeorgia[.

]com; denverplumbingandwaterheater[. ]com; restoremental[. ]com; glowmedaesthetics[. ]com; marbellaresales[.

]com; gatemaden[. ]space; beaocnagent[. ]com; hbubagent[. ]com: MacSync delivery and control domains - Domain arkypc[.

]com; harbor-29[. ]com; fern-plume[. ]com; node-slate[. ]com; grove-12[.

]com; verse-18[. ]com; lakhov[. ]com; mpasvw[. ]com; ouilov[.

]com; aforvm[. ]com: AMOS helper and tasking domains - Domain loop-lumen[. ]com; umapla[. ]com; glrack[.

]com: Fake wallet delivery domains - Domain desktop-version[. ]com; oakenfjrod[. ]ru: Windows staging domains - Domain sic180[. ]com; habar55[.]namebright[.

]bike: SIC Windows-route domains - Domain crisp-paths[. ]com; cli-guides[. ]com; macdeveloper[. ]com: Cryptocurrency wallet 0xA1E50DaF64fb2B342A64d848E396700962acC2d0; 1PbWWqgKDBDorh525uecKaGZD21FGSoCeR; 31kwGkJP9xM26cnQJLpe1CH6pjSt4DEDz2; 32Epo1K92Xzo6Hayq1Fmkj21x4fUk7JZT7; bc1qcg5sx6a6evx5ls4gj6nh8d0jtamh89n2y473dr; bnb1jvds8pg6zkxd2s7dl8klr0dye5avlfv8mm25jm; bc1pqn73hlel3mmnza0kfl2alwkkgkapeeknufgtysll8fs2z4umdf0qpvus9q; ltc1qk437ykzdxms9k9wh5vhd7aalsv0tfx6r39rrtv; LV9AYZKQEg891crnof7PFK6u77noVM4Y45; MG1FerSxboiwjhvU2cv4n34pXz5FpC88p4; TNf4nzc6x6fZrBMLMaZZGV1SbCjShDqbaQ; r9yMnTm4NSzvG9rrwjM2ec8xZgh1cafXH8; cosmos1k5xu6njlc90r92gdwvtfjh826jduw7ptmry0q8; UQDvDUxFShoWWbHougyHjr0tFz3E38fX8e0bnTUpya-P0mXW; DH9W9S6mSSBsGeiSstgsGdiREZupQbZf9C: AnimateClipper and ZigClipper cryptocurrency address-replacement targets - Domain addr1q96640zpnccyktlmjqnzqnypwugva9g9dcuk0f5jt9mjz3xh54zest5mg6mqh9d: Stake1u8t623vc96d5ddstjk46q2l59jeg38y3d0g2asqzf2n2ntqjv72k8; X-avax1h9qxee0820ezfkgeeuc02gkc0c77xrypx8z6g2; bitcoincash:qqkmn6qq7k0wpa5x7qxze5c4lkcsjkrsvsy2ecll6y; bnb1jvds8pg6zkxd2s7dl8klr0dye5avlfv8mm25jm; bc1qkg288agwvjs9cnmhz2q2f4p0x6nttwwngue7v0; 1EZk7eLw52dErMygLvfKQJJ6KVWk8gPgvE: Wuess clipper cryptocurrency address-replacement targets Monitor your SOC for active malware and phishing threats using MISP, VirusTotal, or your SIEM.