
Fake Browser Update to Atomic macOS Stealer
A freelance designer's personal Mac is lured by a ClearFake 'your browser is out of date' prompt into downloading a fake Safari update. The bundled app is Atomic macOS Stealer: it phishes the login password, raids the keychain and browser stores, and uploads the loot to a single host over the same channel it uses to communicate. Reconstruct the chain from the macOS endpoint telemetry and the web filter.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Establish how the machine was lured
10A freelance designer's personal MacBook started uploading data to an unfamiliar host this morning, minutes after the owner says they installed a browser update. Start at the very beginning: how did a routine browsing session turn into a malware download?
Identify the file that was downloaded
15The fake-update page offered a download. macOS updates never arrive this way. Pin down exactly what landed on disk so you know what the user actually ran.
Name what executed on the endpoint
15Downloading a disk image is harmless until something runs. Use the endpoint process evidence to identify the application that the user launched from the mounted image.
Pin down the credential theft
15This is a stealer, so the goal is secrets. Determine how it got at the stored credentials on a Mac, beyond the password it phished with a fake dialog.
Follow the stolen data out
15The collected secrets did not stay on the machine. Find where the stealer sent them.
Classify the exfiltration
15Wrap up by mapping how the data left the machine to MITRE ATT&CK. The stealer did not stand up a dedicated upload server: it reused its command channel.
6 tasks · 85 points total
Training Tools
Skills You'll Build
Ideal for newcomers to SOC operations. Guided investigation with clear indicators.
Prerequisites
- No prior experience required
- Familiarity with XDR concepts
- Familiarity with SIEM concepts
Ready to investigate?
More Operations
View allVPN Brute Force: Credential Attack on the Remote-Access Portal
A password-spray campaign targets the Halcyon Freight SSL-VPN portal from two rotating source IPs, submitting credentials across many accounts to stay under per-account lockout thresholds. One account eventually matches. Reconstruct the spray, identify the compromised account and the operator IP that opened the active session, and trace the first move the attacker made over the tunnel.
UNC6384: Captive-Portal PlugX Implant
A diplomat's managed laptop on an untrusted conference network has its captive-portal check hijacked and is steered to a page posing as a security update. The download is a signed Canon utility paired with a malicious DLL: running the trusted binary side-loads the DLL, which runs PlugX in memory, beacons to a single HTTPS host, and sets a Run key. Reconstruct the chain from the proxy, Sysmon, endpoint, and firewall evidence.
Fighting Ursa: Car-for-Sale Lure to HeadLace
A diplomatic attache clicked a link offering a discounted vehicle for sale, and a trusted Windows program started behaving like malware. Follow the chain from a spearphishing link through an abused web-service redirector and a staged archive to a side-loaded HeadLace loader running under a legitimate signed binary.