SL A.I CyberSecurity Scoring
SL
Company Information
Website:https://www.securityledger.com
Employees number:1
Number of followers:839
NAICS:519131
Industry Type:Online Audio and Video Media
Homepage:securityledger.com
SL Risk Score (AI oriented)
Between 700 and 749
SLOnline Audio and Video Media
Updated:
29/07/2026
29/07/2026
716/1000
Moderate
Ba
SL Global Score (TPRM)
xxxx
SLOnline Audio and Video Media
Score locked

SLModerate
Current Score
716Ba (MODERATE)
01000
2 incidents
-19.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
717
JULY 2026
736
Cyber Attack
29 Jul 2026 • SL
Google, Apple, Trezor, Ledger and Discord: macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets
Mac Users Targeted in ClickFix Campaign Delivering Atomic Stealer Malware
716
CRITICAL-20
APPDISTREGOOTHE1785342399
Mac Users Targeted in ClickFix Campaign Delivering Atomic Stealer Malware
A new ClickFix social engineering campaign is targeting macOS users, tricking victims into manually installing Atomic macOS Stealer (AMOS) malware by disguising malicious commands as routine verification steps.
The attack begins when users encounter a fake CAPTCHA or error prompt on a compromised or fraudulent website, instructing them to copy a command, open Terminal, and execute it ostensibly to complete a security check. Unlike traditional exploits, this method relies on deception rather than software vulnerabilities, leveraging trust in familiar security prompts to coerce victims into executing the infection themselves.
Once the command runs, it downloads a hidden disk image (DMG) containing Atomic Stealer, which operates stealthily mounting without visible indicators in Finder or on the desktop. The malware may then display a counterfeit macOS authentication dialog, tricking users into entering their password to grant elevated privileges.
Atomic Stealer’s capabilities are extensive, targeting:
- Browser data: Saved credentials, cookies, autofill details, and payment information from Chromium-based browsers (Chrome, Edge, Brave, Opera, etc.) and Firefox.
- System credentials: Apple Keychain passwords, Safari cookies, and Apple Notes.
- Messaging apps: Telegram and Discord desktop data, enabling attackers to impersonate victims or access sensitive communications.
- Cryptocurrency assets: Desktop wallets (Exodus, Electrum, Atomic Wallet, Ledger, Trezor, etc.) and 200+ crypto-related browser extensions, with the ability to replace legitimate wallet apps with malicious versions.
- Files: PDFs, TXT, and RTF documents.
Stolen data is compressed into a ZIP archive and exfiltrated to an attacker-controlled server, where it can be used for account takeovers, financial theft, or follow-on scams.
Kaspersky’s report highlights that ClickFix lures, previously focused on Windows users, are now expanding to macOS, employing tactics similar to a recent Script Editor campaign that also relied on social engineering. The attack’s effectiveness stems from bypassing technical defenses by exploiting user trust victims unknowingly authorize the malware’s installation and grant administrative access.
Legitimate websites never require Terminal commands for verification, and macOS users are advised to treat unexpected password prompts with skepticism. The campaign underscores the growing threat of malware-as-a-service (MaaS) tools like Atomic Stealer, which lower the barrier for cybercriminals targeting Apple’s ecosystem.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
736
MAY 2026
735
APRIL 2026
735
MARCH 2026
734
FEBRUARY 2026
734
JANUARY 2026
734
DECEMBER 2025
733
NOVEMBER 2025
732
OCTOBER 2025
750
Cyber Attack
01 Oct 2025 • SL
Ledger and Trezor: New SilabRAT Trojan Hijacks Sessions to Steal Crypto
SilabRAT: A Stealthy Crypto-Draining Malware Emerges as MaaS
731
CRITICAL-19
TRETHE1781108679
SilabRAT: A Stealthy Crypto-Draining Malware Emerges as MaaS
A new remote access trojan (RAT), SilabRAT, has surfaced on dark web forums, designed to bypass passwords and multi-factor authentication (MFA) by hijacking active user sessions to drain cryptocurrency. First advertised in late 2025 by a Russian-speaking threat actor known as o1oo1, the malware is offered as a malware-as-a-service (MaaS) for $5,000 per month. Buyers who often distribute it via email spam and ClickFix lures have reported success rates, with over 90% of infected machines remaining online during month-long campaigns.
SilabRAT evades detection by disguising itself as HijackLoader, a known packer, rather than its true payload. Its standout features include:
- Hidden Virtual Network Computing (HVNC): Operators control infected machines without visible windows or cursor movement, making activity appear as legitimate user sessions.
- Browser-Profile Cloning: The malware copies entire browser profiles including extensions, storage, and device fingerprints to an attacker’s system, allowing stolen sessions to persist even after logouts. A Target.dll module ensures the cloned profile loads seamlessly on the victim’s device.
The malware’s primary goal is cryptocurrency theft. A background module scans for wallets upon infection, attempting to crack passwords using credentials harvested from the victim’s browser. It bypasses Chrome’s App-Bound Encryption via a COM-elevation technique and includes a clipboard clipper to swap wallet addresses mid-transaction. Additional capabilities include:
- Keystroke logging and clipboard monitoring
- Remote desktop access via TightVNC
- A UAC bypass previously used by LockBit and BlackMatter
- Persistence through registry keys or scheduled tasks
Group-IB, which analyzed the threat, warns that SilabRAT’s developer plans to expand its reach by injecting code into Electron-based wallet apps, such as Ledger Live and Trezor Suite. While traditional defenses like MFA and patching can help, the malware’s session-hijacking tactics allow it to bypass even secured logins.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2025
750
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for SL ??
What was SL's A.I Rankiteo Cyber Score in July 2026 ??
What was SL's A.I Rankiteo Cyber Score in June 2026 ??
What was SL's A.I Rankiteo Cyber Score in May 2026 ??
What was SL's A.I Rankiteo Cyber Score in April 2026 ??
What was SL's A.I Rankiteo Cyber Score in March 2026 ??
What was SL's A.I Rankiteo Cyber Score in February 2026 ??
What was SL's A.I Rankiteo Cyber Score in January 2026 ??
What was SL's A.I Rankiteo Cyber Score in December 2025 ??
What was SL's A.I Rankiteo Cyber Score in November 2025 ??
What was SL's A.I Rankiteo Cyber Score in October 2025 ??
What was SL's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on SL's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with SL ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view SL's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?