Atomic Stealer, also known as AMOS or AtomicStealer, is a macOS information stealer. It is designed to collect saved browser credentials, cookies, addresses, payment details, and other browser-resident data, enabling theft of credentials and authenticated web sessions. It has been distributed through social-engineering campaigns, including fake software or developer-tool websites, ClickFix-style paste-and-run lures, malicious advertisements, and disguised companion applications. UNC7005, also tracked as STORM-2945, used Atomic Stealer in a summit-themed campaign against academics, diplomats, and researchers focused on Russia and former Soviet states; macOS victims were served Atomic while Windows victims received Vidar. Atomic Stealer has also been observed in malicious installer campaigns impersonating OpenClaw repositories. The malware targets macOS systems and is associated with financially motivated information-theft activity as well as use in espionage-oriented intrusion campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC7005 distributes information-stealing malware. The group deploys VIDAR for Windows and ATOMIC for macOS disguised as conference companion applications.
Windows visitors received VIDAR, while macOS users received ATOMIC, two malware families built to collect saved browser data such as credentials, cookies, addresses, and payment details.
"...distribute... information stealers, such as Atomic (AMOS), Lumma, Rhadamanthys... and Vidar..."
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Some adversaries have used lures designed specifically for macOS users that encourage the user to open Spotlight, then macOS Terminal to execute malicious commands.
In most scenarios, once users interact with the Fix or Verify button in the lure, the button will covertly copy an obfuscated PowerShell command to the clipboard and present the user with “verification steps.”
Windows visitors received VIDAR, while macOS users received ATOMIC, two malware families built to collect saved browser data such as credentials, cookies, addresses, and payment details.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
macOS information-stealing malware distributed by UNC7005 under the guise of conference companion applications.
A macOS-focused information stealer used in this campaign to collect saved browser data such as credentials, cookies, addresses, and payment details.
A macOS infostealer operating as a malware-as-a-service style offering, used to steal user data from infected systems.
Commodity infostealer used by UNC7005 to steal data from Windows and macOS systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.