LastPass has issued a warning about a sophisticated cybercrime campaign targeting macOS users through fake software distributed via fraudulent GitHub repositories. The attack uses malicious applications disguised as popular software to deliver the dangerous Atomic (AMOS) info-stealing malware.
## How the Attack Works
Cybercriminals have created numerous fake GitHub repositories impersonating over 100 legitimate software products, including LastPass, 1Password, Dropbox, Adobe After Effects, and Audacity. These malicious repositories are optimized to appear high in Google and Bing search results, making them easily discoverable by unsuspecting users.
The attack follows a “ClickFix” pattern where victims are directed to download pages containing terminal commands they don’t understand. When users paste these commands into their Mac’s Terminal, the system downloads and installs the AMOS malware, which can steal sensitive data and provide attackers with persistent backdoor access.
## The AMOS Threat
AMOS operates as a malware-as-a-service, available to cybercriminals for $1,000 per month. The malware specializes in stealing personal information from infected computers and has recently been enhanced with backdoor capabilities, allowing attackers to maintain long-term, hidden access to compromised systems.
## Scale and Persistence
The campaign’s scope is extensive, with attackers creating multiple GitHub accounts to host fraudulent repositories. This approach helps them evade takedown efforts and maintain their malicious infrastructure. Even when fake repositories are reported and removed, new ones can be quickly created through automated processes.
## Protection Strategies
To avoid falling victim to these attacks, security experts recommend:
– **Download software only from official sources**: Always use the vendor’s official website or verified app stores
– **Be cautious with terminal commands**: Never run commands you don’t understand, especially those copied from websites
– **Verify macOS compatibility**: If official macOS versions aren’t available from the vendor, unofficial alternatives are likely fake
– **Research before downloading**: Ensure any third-party software comes from reputable, community-vetted sources
## The Bigger Picture
This campaign represents a growing trend of ClickFix attacks targeting Mac users. Similar operations have previously impersonated services like Booking.com and used fake advertisements to promote fraudulent solutions to macOS problems.
While LastPass continues monitoring this threat and reporting malicious repositories to GitHub, the automated nature of the attack makes it an ongoing challenge. Users must remain vigilant and follow safe downloading practices to protect themselves from these sophisticated social engineering attacks.
The incident highlights the importance of cybersecurity awareness and the need for users to verify software authenticity before installation, particularly when dealing with unofficial or third-party sources.
