Charlie Cullen
Charlie is employed as a principal intelligence analyst with CrowdStrike’s Intelligence Analysis Cell and focuses on macOS malware, ransomware operators, and cryptocurrency analysis. He previously worked at TRM Labs, Dataminr, and AECOM and has presented at Fal.Con 2019 and 2020, BSides Atlanta 2020, BotConf 2022, and Disruption 2024. He is proficient in Arabic, Farsi, Russian, Spanish, and French.
Session
Prior to 2023, commodity information stealers targeting macOS remained a niche activity rarely found advertised in cybercrime communities. The March 2023 release of COOKIE SPIDER’s Atomic macOS Stealer (aka AMOS) sparked rapid adoption among Russian-speaking “traffer” groups and, subsequently, the rise of many competitor stealer projects that continue to proliferate to this day.
This talk will trace the origins of AMOS and its main operator, COOKIE SPIDER, as well as profile its major competitors, touching on similarities and differences between each malware family, their customers, and novel distribution methods and trends. We will also showcase the use of crypto analysis to map relationships between stealer vendors, their customers, and their infrastructure.
The presentation will also highlight the ecosystem in which macOS malware vendors and users exist including the monetization of their infections via cryptocurrency theft, sale of logs, and the emergence of some of the first Pay-Per-Install (PPI) services leveraging macOS infections. We will also conclude our talk with a look at recent and future trends in commodity macOS malware development.