MalwareBazaar Database

This page shows some basic information the YARA rule Gibberdrop_AMOS_ConfigRolXor including corresponding malware samples.

Database Entry


YARA Rule:Gibberdrop_AMOS_ConfigRolXor
Description:AMOS macOS stealer (mainline panel builds) - rolling-key XOR decrypt loop of the embedded __data config (key rotated right by 1 per byte), arm64 and x86_64
Firstseen:2026-09-28 06:19:47 UTC
Lastseen:2026-09-28 06:19:53 UTC
Sightings:5

Malware Samples


The table below shows all malware samples that matching this particular YARA rule (max 1000).

Firstseen (UTC)SHA256 hashTagsSignatureReporter