CogNoodle Advocacy investigates, documents, and exposes real-world cybersecurity threats β from malware campaigns to AI-powered social engineering β so the world can fight back.
We believe cybersecurity awareness shouldn't be locked behind paywalls or corporate firewalls. CogNoodle Advocacy makes threat intelligence accessible to everyone.
Real-time investigation of active malware campaigns, social engineering attacks, and threat actor infrastructure. We document everything so the community can learn.
Translating complex threat intelligence into actionable guidance. From IOC databases to plain-language advisories, we help individuals and organizations defend themselves.
Filing reports with federal agencies (FBI, CISA, FTC), coordinating with platform vendors, and advocating for policy changes that make the internet safer for everyone.
A multinational malware delivery operation leveraging a Chinese AI platform to distribute Russian-origin macOS infostealer malware through Brazilian command-and-control infrastructure.
On February 26, 2026, CogNoodle researchers encountered a ClickFix social engineering attack on kimi.com (Moonshot AI) that attempted to deliver AMOS (Atomic macOS Stealer) via fake system dialogs triggering curl|bash payloads. The download attempt was unsuccessful based on available evidence.
Read Full Investigation Report β| Type | Indicator | Context |
|---|---|---|
| Domain | contatoplus.com | C2 server β Brazilian hosting |
| IP | 191.101.236.x | Contabo GmbH VPS (ASN 174) |
| Domain | kimi.com | Delivery vector β injected ClickFix |
| Technique | Base64 β curl|bash | Encoded C2 URL in clipboard payload |
| Malware | AMOS (Atomic macOS Stealer) | Russian-origin MaaS via Telegram |
CogNoodle has filed formal reports with federal cybersecurity and law enforcement agencies regarding the ClickFix/AMOS threat campaign.
Formal cybercrime complaint filed with the FBI IC3 detailing the multinational attack chain and threat actor infrastructure.
ic3.gov βVulnerability disclosure and threat intelligence report submitted to CISA for national cybersecurity awareness coordination.
cisa.gov βConsumer protection report filed documenting deceptive tactics used in the ClickFix social engineering campaign.
reportfraud.ftc.gov βMalicious URL and phishing site report submitted to Google's Safe Browsing team for browser-level threat protection.
safebrowsing.google.com βIf you've encountered suspicious activity, malware, or social engineering attacks, contact us. We investigate, document, and file reports with the appropriate authorities.
Contact CogNoodle Security