Campaign record
AMOS via a shared delivery layer
Shared AMOS Stealer delivery layer behind the kusaka.php redirect gate
- Status as last assessed
- Active
- First seen
- 2024-05-01
- Last seen
- Unrecorded
- Indicators
- 20
- Sources
- 1
- Targets
- macOS
- AMOS (Atomic macOS Stealer)
- Traffers affiliate distribution
- Traffic distribution system (TDS)
Original research
- Sekoia.io2024-10-17Vendor researchFirst account
ClickFix tactic: The Phantom Meet
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
One delivery layer sits behind a range of unrelated lure pages aimed at Mac users. A request to a PHP script named kusaka on any of twenty hosts returns a redirect in the Location header, and only the second request, to a long hashed path on the same host, hands over the disk image. Sekoia has tracked the pattern since May 2024 and reads the arrangement as rented rather than owned: one endpoint fielded traffic from many different front ends, which points to a central crew supplying both the delivery chain and the stealer to affiliates. The publisher also treats the gate as a filter against scanners and bots. Nothing in the report says whether these twenty domains were registered by the operators or belong to sites that were broken into, so none is recorded here as attacker property.
Overlap with other campaigns
We compared the 20 indicators in this record — covering 20 distinct registrable domains — against the 43 other published campaigns in this corpus.
Google Meet clones, three stealers
2026-08-071 of the 20 indicators in AMOS via a shared delivery layer also appear in this campaign.
Shared registrable domain (1)
- domain, shown defanged for safety: carolinejuskus dot com
A shared indicator is the same record cited by both campaigns. A shared registrable domain is weaker evidence and is counted separately, because two campaigns can share a registrable simply by renting subdomains from the same platform.
Indicators
20 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator. No observation date is recorded for any of them.
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account, our own re-checks of these indicators or a recorded execution mechanism. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “AMOS via a shared delivery layer”, campaign ID de6108c0, retrieved 2026-08-07, snapshot fb0eed7.
https://clickfixreport.com/campaigns/de6108c0/amos-stealer-kusaka-distribution
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.