Uptime Hamster: 10d 11h 42mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza COOKIE SPIDER

COOKIE SPIDER

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Ver en IntelTracker → APTTrail →
COOKIE SPIDER is a cybercriminal group that emerged in June 2025, operating a Malware-as-a-Service (MaaS) platform to distribute SHAMOS, a variant of the Atomic macOS Stealer (AMOS). This group specifically targets macOS users through malvertising campaigns, luring them to fraudulent websites to steal sensitive information and cryptocurrency assets. Its operations are notable for deliberately avoiding victims in Russia and Commonwealth of Independent States (CIS) countries, a practice attributed to adherence to regulations within certain Eastern European cybercriminal forums where the group likely operates. COOKIE SPIDER distinguishes itself by focusing exclusively on macOS users with high-volume, opportunistic campaigns that leverage social engineering and technical evasion to bypass native macOS security features.

Actores similares

Scattered Spideractor · 2Indrik Spideractor · 1doppel-spideractor · 1salty-spideractor · 1brain-spideractor · 1skeleton-spideractor · 1bamboo-spideractor · 1andromeda-spideractor · 1cobalt-spideractor · 1boson-spideractor · 1
Tecnicas MITRE
T1027 - Obfuscated Files or Information, T1005 - Data from Local System, T1087 - Account Discovery, T1115 - Clipboard Data, T1571 - Non-Standard Port, T1583 - Acquire Infrastructure
CVEs relacionadas
CVE-2025-61882, CVE-2025-49706, CVE-2025-49704, CVE-2025-41244, CVE-2025-32406, CVE-2024-48248
Tipo
apt
Pais origen
RU
Motivacion
-
Impacto
79
Actualizado
Tue, 02 Se

Paises objetivo (SOCRadar)

BrazilCanadaChinaColombiaFranceUnited KingdomGeorgiaIndiaItalyJapan

Sectores objetivo (SOCRadar)

Software PublishersManufacturingPublic AdministrationInternet PublishingEnergy & Utilities InsuranceAutomotiveNational Security&International AffairsTelecommunicationsTransportation&Warehousing