AMOS Stealer, also known as Atomic macOS Stealer, is a macOS-focused information-stealing malware family commonly operated as malware-as-a-service. It targets Apple systems and is used in financially motivated campaigns to steal credentials, browser data, session cookies, cryptocurrency wallet data, Telegram data, keychain material, and selected user documents. The malware has been observed collecting data from Chromium- and Gecko-based browsers, Safari-related artifacts, desktop wallet applications, and developer- or enterprise-relevant files such as SSH, cloud, and shell configuration material. Some variants also use fake password prompts to obtain the user’s macOS password and attempt to access protected credential stores.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
ClearFake is a malicious JavaScript framework deployed on compromised websites to deliver malware through the drive-by download technique.
An active malware distribution campaign abusing two prominent AI platforms Hugging Face and ClawHub to deliver trojans, cryptominers, and infostealers disguised as legitimate AI tools and agent extensions. The campaign marks a significant evolution in supply chain attacks, shifting from traditional software repositories to trusted AI ecosystems.
Shown above: Text from the fake Brew page pasted into a terminal Window.
The AMOS Stealer is a macOS malware known for its data theft capabilities, often delivered via an encrypted osascript (AppleScript) payload.
Once the script is downloaded, it automatically launches an AppleScript command using the zsh terminal shell to begin collecting data.
MacOS maintains a list of applications that should be automatically opened when a user logs in. This list is stored in the com.apple.loginwindow preferences domain under the key AutoLaunchedApplicationDictionary ... it is the programmatic equivalent of a user manually adding an app to their “Login Items” in System Settings.
MacOS maintains a list of applications that should be automatically opened when a user logs in. This list is stored in the com.apple.loginwindow preferences domain under the key AutoLaunchedApplicationDictionary ... it is the programmatic equivalent of a user manually adding an app to their “Login Items” in System Settings.
For Windows targets, payloads were detected as trojans packed with VMProtect... A second Windows payload used a 30-byte XOR key to decrypt strings at runtime... The FAKESECURITY campaign used a batch script (CDC1.bat) containing an encoded PowerShell blob...
After a successful upload, Amos Stealer runs the cleanup commands ( rm -f /tmp/osalogging.zip and rm -rf /tmp/sync ) to erase its presence.
AMOS Stealer often employs anti-VM techniques to evade analysis in sandboxed environments, typically by querying system information to detect virtualization signatures like QEMU or VMware.
Prompts for the system password if needed, using a deceptive dialog disguised as a legitimate "System Preferences" request.
It then collects stored passwords, session cookies, and autofill form information from Google Chrome and Microsoft Edge browsers.
System Information : Captures hardware, software, and display details using system_profiler .
File Grabber : Collects files with specific extensions (e.g., .txt, .pdf, .docx, .wallet, .key) from Desktop, Documents, and Downloads folders
Prompts for the system password if needed, using a deceptive dialog disguised as a legitimate "System Preferences" request.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS stealer referenced as lineage/comparison for MacSync. The content says MacSync shares AMOS-style AppleScript execution, fake password prompts validated with dscl authonly, Safe Storage key theft, browser and wallet collection, and poisoned-search delivery patterns.
A macOS-focused information stealer used in financially motivated campaigns. It steals browser passwords, session cookies, autofill data, copies the macOS Keychain database, collects developer configuration files and keys, compresses stolen data, exfiltrates it to attacker-controlled infrastructure via curl, and removes artifacts afterward.
A macOS-focused infostealer delivered in this campaign via malicious AI platform content; it is described as being sold as malware-as-a-service through Telegram and underground forums.
A macOS-focused infostealer distributed via malicious OpenClaw skills in this campaign. It is delivered through staged shell scripts that download and execute the payload from attacker-controlled infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.