Homebrew MacOS MALWARE! | Decrypting Cuckoo Stealer using Python

Опубликовано: 11 Апрель 2026
на канале: Jai Minton - CyberRaiju
1,953
86

Threat actors typo-squatting the Homebrew domain are attempting to steal credentials from MacOS systems.

Let's look at how we can analyse this malicious Mach-O binary to understand what it is doing and decrypt AMOS (Atomic MacOS Stealer) using Python.

Update: It's been brought to my attention that the malware I had is actually part of the Cuckoo family rather than Atomic MacOS Stealer. Some homebrew domains would serve AMOS and others would serve Cuckoo. Updating with some further reading below:

https://alden.io/posts/infostealers-a...
https://blog.kandji.io/malware-cuckoo...

** Find me at **
Twitter/X -   / cyberraiju  
Blog - https://www.jaiminton.com/
Mastodon - https://infosec.exchange/@CyberRaiju

** Tools **
FLARE VM - https://github.com/mandiant/flare-vm
Urlscan - https://urlscan.io/
XMachOViewer - https://github.com/horsicq/XMachOViewer
Detect-It-Easy - https://github.com/horsicq/Detect-It-...
Ghidra - https://github.com/NationalSecurityAg...
7-Zip - https://7-zip.org/

** Sample **
https://bazaar.abuse.ch/sample/ce6dc0...
https://www.virustotal.com/gui/file/c...
https://www.vmray.com/analyses/_vt/ce...

** Website Scans **
https://urlscan.io/result/d47583c5-aa...
https://urlscan.io/result/29856c41-20...

** Further Reading **
https://objective-see.org/blog/blog_0...
https://x.com/phd_phuc/status/1651001...
https://x.com/ShanHolo/status/1789561...
https://developer.apple.com/library/a...
https://stackoverflow.com/questions/1...
https://www.redhat.com/sysadmin/how-m...
https://learn.microsoft.com/en-us/win...

** Timestamps **
00:00 - Intro
00:28 - Malicious website analysis
00:40 - AMOS Stealer overview
01:12 - Twitter OSINT
01:41 - Dynamic analysis using VMRay
04:09 - Objective See analysis
04:57 - Static analysis using xmachoviewer
05:25 - Static analysis using Detect It Easy
08:47 - Extracting macho with 7-Zip
09:09 - Static analysis with Ghidra
10:11 - Analysis of decryption operation
11:12 - Creating a decryption Python script
14:00 - Locating encrypted bytes
16:50 - Decrypting strings with Python
18:00 - Renaming decryption function
18:20 - Finding encrypted strings in binary sections
19:26 - Locating C2 information
19:57 - Analysis of all encrypted strings
22:18 - Outro

Credits:
SFX by Pixabay