Atomic macOS Stealer infection surge hits Mac users

A fresh Atomic macOS Stealer (AMOS) infection reported on Sunday, August 2 underscores how the malware-as-a-service operation continues to pose a serious risk to macOS users worldwide[1][5][7]. The latest case, shared within the malware research community, fits into an ongoing wave of campaigns that aggressively target everyday Mac users rather than high-profile enterprises[1][4][9]. Researchers say AMOS activity has remained steady through 2025 and 2026, with operators rapidly iterating on delivery techniques and payload capabilities to evade defenses and maximize data theft[4][5][9].

AMOS is an information-stealing malware family designed to siphon sensitive data directly from infected Apple devices, including browser cookies, passwords, autofill data, and cryptocurrency wallet contents[4][9][10]. Once a user is tricked into executing the initial command or installer, the malware typically runs a bootstrap script, captures and validates the victim’s macOS password, then retrieves a second-stage payload that executes with elevated privileges[4][15]. Sophos researchers describe how AMOS runs extensive anti-analysis checks, collects keychain databases, browser profiles, Apple Notes, and host system details before archiving everything for exfiltration to attacker-controlled infrastructure[4][9]. More recent variants described by CyberNews embed a backdoor that allows remote command execution, continuous monitoring, and automatic reinstall after reboot, turning an initial infostealer compromise into full system takeover[5].

The August 2 infection appears against a backdrop of increasingly creative delivery vectors that rely on social engineering rather than software vulnerabilities[1][4][9]. In the so-called ClickFix campaigns observed in June and July, victims are instructed to copy a “verification” command from a web page, paste it into Terminal, and run it as part of a fake CAPTCHA or troubleshooting step, which silently downloads and launches a disk image containing AMOS[2][12]. Other operators have used malvertising and SEO poisoning to push fraudulent “help” or download sites that trick users into running a Terminal command or installer posing as legitimate software fixes[4][6][9]. Separate Trend Micro research describes malicious “skills” on AI automation platforms that hide AMOS in project files and prompt users through a human-in-the-loop dialog to enter their password, turning trusted AI workflows into a supply chain for infection[3]. Campaigns linked to cracked or pirated versions of popular macOS applications similarly abuse users seeking free software, with the counterfeit installer acting as a Trojan horse for AMOS deployment[10][13].

The operation behind Atomic macOS Stealer has been characterized as a Russia-linked malware-as-a-service ecosystem that rents access to the malware and victim logs to multiple criminal customers[5][7]. CrowdStrike has documented activity from a group it tracks as Cookie Spider, which it says operates an AMOS-based enterprise and has run large-scale malvertising campaigns between June and August, directing users to fake troubleshooting sites that deliver a variant dubbed SHAMOS[6]. That SHAMOS payload includes anti-virtual machine checks and flexible reconnaissance and data collection capabilities, reinforcing how AMOS has evolved into a modular platform for monetizing stolen macOS data[3][6]. CyberNews reporting estimates that AMOS has already infected thousands of machines across more than 120 countries, with particularly heavy impact in the United States and major European nations[5].

For defenders, the August 2 case is another reminder that preventing AMOS infections hinges on hardening user workflows as much as patching software[1][4][9]. Sophos recommends monitoring for user-initiated Terminal “paste-and-run” behavior, enforcing Gatekeeper and notarization policies, and keeping Apple’s XProtect and macOS security updates fully enabled to block untrusted binaries[4]. Telemetry from Anvilogic and others shows AMOS often triggers suspicious AppleScript dialogs via commands like osascript -e display dialog and follows up with credential validation using directory service calls, patterns that can be hunted across endpoint logs[15]. Vendors including Malwarebytes and Broadcom have shipped detection updates for AMOS and ClickFix-style attacks, urging organizations to deploy reputable macOS security tools, remove default local admin rights, and educate users to distrust commands or installers delivered via ads, cracked software, or unexpected “verification” prompts[2][7][10]. With AMOS operators iterating quickly and abusing legitimate web and AI platforms, security teams are treating Mac endpoints as first-class targets and tightening controls before the next wave of infections hits[3][4][9].

References

  1. Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)
  2. AMOS (Atomic macOS Stealer) malware deployed in latest ClickFix …
  3. Malicious OpenClaw Skills Used to Distribute Atomic …
  4. Why AMOS matters: The macOS malware stealing data at scale
  5. This MacBook malware lets Russian hackers remotely control your device
  6. Hundreds Targeted in New Atomic macOS Stealer Campaign
  7. Malwarebytes Threat Alert | OSX.AtomicStealer
  8. Atomic macOS Stealer leads sensitive data theft on macOS | SOPHOS
  9. Mac users targeted in new malvertising campaign delivering Atomic Stealer
  10. macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets
  11. Macs under attack from ‘cracked’ apps spreading dangerous info-stealing malware — don’t fall for this
  12. macOS Infostealers Surge: Atomic, Poseidon, and Cthulhu …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply