How Cybersecurity Pros Are Targeted by Fake Conference Scams Deploying AMOS Infostealer

Security professionals face sophisticated scams involving fake crypto conference invites that prompt macOS users to install the AMOS infostealer, risking sensitive info theft and wallet compromise.

How Cybersecurity Pros Are Targeted by Fake Conference Scams Deploying AMOS Infostealer
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

How Are Security Professionals Targeted by Fake Conference Scams?

Attackers create fake social media profiles imitating organizers of cybersecurity events to engage with past conference attendees. They then direct victims to malicious documents, posing as official info packets for a new event. The deception leads victims to follow instructions that compromise their systems.

What Happens During the Infection Process?

vidar #aitm #raccoon #infostealer #adversary #purpleteam #threathunting  #emergingthreat #threatintel | Bhuvanesh Prabhakaran
vidar #aitm #raccoon #infostealer #adversary #purpleteam #threathunting #emergingthreat #threatintel | Bhuvanesh Prabhakaran

The malicious document contains a fake security feature requiring a decryption code. When the code returns an error, victims are instructed to paste a script into their macOS Terminal. Running this code installs the AMOS infostealer malware, which steals sensitive data like browser history, passwords, cryptocurrency wallet details, and encrypted files.

Continued Attempts and Variations

If the initial infection attempt fails, attackers send follow-up documents impersonating Dropbox, again pushing the victim to download the harmful infostealer executable disguised as legitimate software. Though the Windows version appears less effective, the primary target remains macOS users.

What Are the Risks to Affected Users?

The installed malware can extract confidential credentials, tokens, and private keys, allowing threat actors to access email accounts, developer tools, and cryptocurrency wallets. This leads to potential identity theft, financial loss, and unauthorized system access. Given the tailored nature of this scam, security experts themselves become vectors for further breaches.

What Should You Do If Exposed to This Scam?

Distinct Clusters Target Individuals of Interest to Russia | Google Cloud  Blog
Distinct Clusters Target Individuals of Interest to Russia | Google Cloud Blog
  1. Immediately isolate the affected system from all networks to prevent further data exfiltration.
  2. Conduct forensic analysis to identify the extent of the compromise.
  3. Consider full system reimaging to remove any persistent threats.
  4. Reset and rotate all credentials including passwords, API keys, and digital certificates.
  5. Revoke active sessions across all user accounts involved.
  6. Thoroughly review all cryptocurrency wallets for unauthorized transactions or access.

What Can Cybersecurity Professionals Learn From This?

This targeted campaign highlights the need for vigilance even among experienced professionals. Familiarity with social engineering tactics and cautious handling of unsolicited links or code requests, especially in Terminal environments, is critical. Always verify event invitations through official channels and avoid executing untrusted scripts. Educating teams about these attack vectors can prevent costly breaches.

React to this story

Related Posts