Google Doc Sidebar Delivers Cross-Platform Stealer Malware
Score: 7/10

Google Doc Sidebar Delivers Cross-Platform Stealer Malware

An adversary uses malicious Google Apps Scripts in Google Doc sidebars to deliver AMOS and NetSupport Manager malware targeting both macOS and Windows users.

Executive Summary

A sophisticated social engineering campaign has been identified leveraging Google Doc sidebars to distribute platform-specific malware. Attackers pose as industry executives on social media (specifically X) to lure victims toward a legitimate Google Doc. The document contains a malicious Google Apps Script that serves as a triage mechanism, identifying the victim's operating system, location, and presence of cryptocurrency wallets before delivering a tailored payload.

Technically, the campaign uses 'ClickFix' lures, where a fake decryption error prompts users to execute terminal commands or download 'manual updates.' macOS users are targeted with variants of the AMOS (Atomic macOS) stealer, while Windows users are infected with a multi-stage PowerShell loader chain. This chain is notable for abusing stolen code-signing certificates from legitimate companies like Discord and Lenovo to bypass security warnings.

This threat is high-impact due to its focus on stealing cryptocurrency credentials and its persistence mechanisms, including a rogue certificate authority (CA) that enables local HTTPS interception. Organizations, particularly those in the financial and technology sectors, should be wary of unsolicited documents and the execution of unverified terminal commands.

Key Details

Threat Name

AMOS Stealer via Google Doc Sidebar

Affects

—

Adversary

—

Malware/Tools

AMOS, MacSync, NetSupport Manager

Report Score

7out of 10
Quality Score
Good
IOC Quality6
TTP Details8
Detection Guidance5
Enterprise Relevance9
Clarity & Structure7
Technical Depth8

Sources