Skip to main content
Fake Browser Update to Atomic macOS Stealer operation cover
BeginnerXDRSIEM

Fake Browser Update to Atomic macOS Stealer

A freelance designer's personal Mac is lured by a ClearFake 'your browser is out of date' prompt into downloading a fake Safari update. The bundled app is Atomic macOS Stealer: it phishes the login password, raids the keychain and browser stores, and uploads the loot to a single host over the same channel it uses to communicate. Reconstruct the chain from the macOS endpoint telemetry and the web filter.

25m
6 tasks
25 points
Free

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Establish how the machine was lured

10

A freelance designer's personal MacBook started uploading data to an unfamiliar host this morning, minutes after the owner says they installed a browser update. Start at the very beginning: how did a routine browsing session turn into a malware download?

SOC{host.domain.tld}Hint available
2

Identify the file that was downloaded

15

The fake-update page offered a download. macOS updates never arrive this way. Pin down exactly what landed on disk so you know what the user actually ran.

SOC{filename.ext}Hint available
3

Name what executed on the endpoint

15

Downloading a disk image is harmless until something runs. Use the endpoint process evidence to identify the application that the user launched from the mounted image.

SOC{process}Hint available
4

Pin down the credential theft

15

This is a stealer, so the goal is secrets. Determine how it got at the stored credentials on a Mac, beyond the password it phished with a fake dialog.

SOC{Txxxx.xxx}Hint available
5

Follow the stolen data out

15

The collected secrets did not stay on the machine. Find where the stealer sent them.

SOC{a.b.c.d}Hint available
6

Classify the exfiltration

15

Wrap up by mapping how the data left the machine to MITRE ATT&CK. The stealer did not stand up a dedicated upload server: it reused its command channel.

SOC{Txxxx}Hint available

6 tasks · 85 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
XDR log analysis
SIEM log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Beginner

Ideal for newcomers to SOC operations. Guided investigation with clear indicators.

Prerequisites

  • No prior experience required
  • Familiarity with XDR concepts
  • Familiarity with SIEM concepts

Ready to investigate?

More Operations

View all