Atomic Stealer (AMOS) is a macOS-focused infostealer that debuted in 2023 and was prolific in 2024. It is associated with a malware-as-a-service model and was reportedly offered by subscription, with pricing increasing from $1,000 to $3,000 per month. The malware targets both home and business Mac users and is part of a broader macOS infostealer ecosystem that has increasingly relied on social engineering and malvertising.
AMOS is designed to steal credentials and other sensitive data from macOS systems. High-confidence reporting in the provided content states that it abuses AppleScript via osascript, including hidden answer parameters, to trick users into entering their macOS password; this enables unlocking of the Keychain for credential theft. Newer variants use encrypted strings and remotely loaded AppleScript for evasion. The content also links the AMOS family to theft of passwords, credit card details, cryptocurrency, and other sensitive information. A fork of AMOS, Poseidon, is described as stealing data from over 160 cryptocurrency wallets, browsers, Bitwarden, KeePassXC, FileZilla, and VPN configurations such as Fortinet and OpenVPN.
Distribution heavily relies on malvertising and fake download sites. The content states that AMOS campaigns use malicious Google and Bing ads, fraudulent high-ranking websites, malicious GitHub repositories, and one-line Terminal commands that bypass Gatekeeper. One observed campaign directed users to fake macOS help sites with ClickFix-style instructions that convinced victims to open Terminal and paste a command, resulting in download of a variant called SHAMOS. The malware family also includes variants such as Poseidon (also referred to as Rodrigo) and Cuckoo.
Overall, AMOS is a prominent macOS infostealer family characterized by credential theft, Keychain access through password-prompt deception, evasion improvements, and widespread delivery through malvertising and fake software or support pages.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
A bad actor was “using those login sessions to access Claude accounts and consume their usage.”
A bad actor [is] using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage.
When the victim runs the Terminal command, the campaign retrieves and executes a remote script from a /curl/<id> URL.
These commands typically launch PowerShell, which retrieves and executes remote payloads, thereby enabling the deployment of information stealers and other malicious applications.
Defenders should monitor for browsing followed by unusual Terminal activity, especially curl piped into zsh, Base64 decoding, osascript, and archive creation followed by outbound HTTP POST requests.
...luring the user into downloading the infostealers MacSync and Atomic Stealer (AMOS).
Earlier pages exposed the ClickFix instructions, clipboard logic, obfuscated shell command, and encoded staging address directly in their HTML, making them easy for static scanners to recover.
The page uses GitHub-themed branding to mimic a legitimate software download experience; the branding is spoofed and does not indicate any compromise of GitHub.
A bad actor was “using those login sessions to access Claude accounts and consume their usage.”
A bad actor [is] using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage.
The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download.
The gate's script, about 2.5 KB of JavaScript, reads navigator values such as the platform string, which should report MacIntel on a real Mac, along with screen and window dimensions and WebGL graphics signals that help separate genuine Apple hardware from a virtual machine or an emulated environment. It checks the timezone, whether the page is boxed inside an iframe, and whether the device reports touch support, which desktop Macs generally do not.
“Infostealer malware on their systems has stolen active Claude login sessions” and can “copy an already verified session,” avoiding the password and multi-factor login process.
The malware “steals locally stored data such as login cookies, app credentials, and browser passwords.”
The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download.
The gate's script, about 2.5 KB of JavaScript, reads navigator values such as the platform string, which should report MacIntel on a real Mac, along with screen and window dimensions and WebGL graphics signals that help separate genuine Apple hardware from a virtual machine or an emulated environment. It checks the timezone, whether the page is boxed inside an iframe, and whether the device reports touch support, which desktop Macs generally do not.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prolific macOS infostealer family that uses AppleScript to harvest credentials, including Keychain data, by tricking users into revealing their passwords. Newer variants use encrypted strings and remotely loaded AppleScript for evasion.
Atomic Stealer (AMOS) is a macOS information stealer distributed via malvertising and social engineering, capable of stealing credentials and downloading additional payloads.
Atomic Stealer (AMOS) is a Mac-focused infostealer that can be licensed by cybercriminals as a service. It is capable of stealing a variety of sensitive information from Mac computers, including passwords and credit card details.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.