Skip to content

Campaign record

AMOS via a fake Spectrum page

Atomic Stealer delivered by Spectrum-themed ClickFix pages aimed at Mac users

Status as last assessed
Active
First seen
2025-05-30
Last seen
2025-06-06
Indicators
12
Sources
2
Targets
macOS, Windows
  • Fake CAPTCHA verification
  • Internet and cable provider impersonation
  • AMOS (Atomic macOS Stealer)
  • Malvertising

Original research

This page summarises and structures that research; it is not a substitute for the original.

Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.

Summary

Reported publicly in June 2025 by CloudSEK and dated by Microsoft to the closing days of May, this operation pointed Mac owners at delivery pages made up to look like Spectrum, the American cable, broadband and telephone company. The page showed a counterfeit CAPTCHA with an alternate verification button; the steps it then displayed were written for Windows even when the reader was on a Mac, while the command placed on the clipboard differed by platform. On macOS that command asks for the account password again and again until one checks out against directory services, keeps it in the temporary folder, pulls a file down from applemacios[.]com, uses the captured password to strip the quarantine flag, marks the file runnable and starts it. The file belongs to the Atomic Stealer family, whose Poseidon and Odyssey variants take browser cookies, saved passwords and cryptocurrency wallet material.

Cross-vendor timeline

2 published accounts. CloudSEK was first, on 2025-06-04. The most recent is Microsoft Threat Intelligence, 78 days later.

  1. 2025-06-04CloudSEK

    AMOS Variant Distributed Via Clickfix In Spectrum-Themed Dynamic Delivery Campaign By Russian Speaking Hackers

  2. 2025-08-21Microsoft Threat Intelligence+78 days

    Think before you Click(Fix): Analyzing the ClickFix social engineering technique

Dates are the publishers’ own publication dates as recorded when we retrieved each article. Publication order is not attribution: a later account may be the more complete one.

Overlap with other campaigns

We compared the 12 indicators in this record — covering 7 distinct registrable domains — against the 43 other published campaigns in this corpus.

  • No indicator is shared, but the two records use the same registrable domains.

    Shared registrable domain (1)

    • domain, shown defanged for safety: pages dot dev

A shared indicator is the same record cited by both campaigns. A shared registrable domain is weaker evidence and is counted separately, because two campaigns can share a registrable simply by renting subdomains from the same platform.

What changed since publication

The accounts above describe these indicators as they were on the day each was written. We re-check them ourselves and record every check, including the ones that find nothing — which is the only reason the gaps below can be stated rather than hidden.

Indicators checked
1 of 12
Checks recorded
2
Checks since publication
2
Never checked
11

Observation window 2026-08-10 to 2026-08-22. Checks are sampled, not continuous; the sampling policy is on /methodology. 11 indicators have never been checked by us at all.

Current recorded state

  • 1 Unregistered
  • 11 Not checked by us

Nothing has changed state between our first check and our most recent one. A domain that still resolves is not necessarily still serving anything — registrar hold pages answer DNS indefinitely, which is why the state above distinguishes “parked or suspended” from “resolving”.

Execution mechanisms

How the pasted command actually ran, as the published accounts describe it. Every row under “Mechanism” is one this campaign records; “Across the corpus” is the share of the 44 published campaigns in this corpus that record the same one — a baseline we can only state because we hold the whole set.

Execution mechanisms recorded for this campaign, with their frequency across the corpus
MechanismAcross the corpusATT&CK
Windows Run dialog23 of 4452%T1204.004
PowerShell19 of 4443%T1059.001
Clipboard injection15 of 4434%T1204.004
Terminal paste (macOS)8 of 4418%T1059.004

No other campaign on record combines them. We record a mechanism only where a source describes one: an absent mechanism means nobody wrote it down, not that it did not happen.

Indicators

12 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.

Indicators recorded for this campaign, shown defanged
IndicatorTypeRoleAssessmentFirst seenLast seenStateReport an error
domain, shown defanged for safety: panel-spectrum dot netdomainLure pageAttacker-controlled2025-05-302025-05-30Not checked by usReport an error in domain record 372599e3-4013-4d6a-8b41-c84475e0cfdd
domain, shown defanged for safety: spectrum-ticket dot netdomainLure pageAttacker-controlledNot checked by usReport an error in domain record 7fae17f6-e241-4dcd-8ae7-1cd40f5ce646
url, shown defanged for safety: hxxps colon slash slash applemacios dot com/getrur/install dot shurlDownload URLAttacker-controlledNot checked by usReport an error in url record 9a541b0e-64e8-42cb-b5bb-8db3d4365ff6
url, shown defanged for safety: hxxps colon slash slash applemacios dot com/getrur/updateurlDownload URLAttacker-controlled2025-05-302025-05-30Not checked by usReport an error in url record b837708e-3c7f-4a14-8e1e-fdad81ff1b12
url, shown defanged for safety: hxxps colon slash slash cf-verifi dot pages dot dev/i dot txturlDownload URLShared platformNot checked by usReport an error in url record c93dc3da-863c-4ca2-b8bf-9967cb82946f
domain, shown defanged for safety: applemacios dot comdomainCommand and controlAttacker-controlled2025-05-302025-05-30Unregistered2026-08-22Report an error in domain record 777603bd-f4f1-48f1-b60d-7c9804e721a6
domain, shown defanged for safety: brewory dot comdomainCommand and controlAttacker-controlledNot checked by usReport an error in domain record 9d1b4867-a1c3-4e30-932d-6c03a0305541
domain, shown defanged for safety: cf-verifi dot pages dot devdomainCommand and controlShared platformNot checked by usReport an error in domain record 37f1fefc-96b9-4624-a2fa-782b995df7f0
domain, shown defanged for safety: homebrewrp dot comdomainCommand and controlAttacker-controlledNot checked by usReport an error in domain record aa8d8e1f-2a23-453d-92f2-0ea06ae0abdc
md5, shown defanged for safety: 6fd092d86235d7ae35c557523f493674md5SampleNot yet assessedNot checked by usReport an error in md5 record 5bc4247e-ed63-46b7-9dbe-0ea81db5891c
md5, shown defanged for safety: eaedee8fc9fe336bcde021bf243e332amd5SampleNot yet assessedNot checked by usReport an error in md5 record 137fdb20-7a2f-4280-acd2-20a37fe2b66f
domain, shown defanged for safety: rugme dot catdomainOtherAttacker-controlledNot checked by usReport an error in domain record be2be522-ec55-4076-8412-bc62c5257836

“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.

Cite as

ClickFixReport, “AMOS via a fake Spectrum page”, campaign ID 1f22b447, retrieved 2026-08-29, snapshot fb0eed7.

https://clickfixreport.com/campaigns/1f22b447/amos-clickfix-spectrum

Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.