AMOS Stealer, also known as Atomic Stealer, is a macOS-focused information stealer offered through a malware-as-a-service model and advertised on Telegram and underground forums since at least April 2024. It targets Apple systems to collect system information, browser-stored passwords, cookies, autofill data, browser extension data, macOS Keychain material, cryptocurrency-wallet data, Telegram Desktop sessions, SSH and cloud-related keys, and selected user documents. It can use deceptive password prompts to obtain account credentials, archive collected data, exfiltrate it to operator infrastructure, and remove temporary collection artifacts. Documented variants use AppleScript and native macOS utilities to execute and conduct collection, and may employ anti-virtual-machine checks and hide Terminal activity. AMOS Stealer has been distributed through fake software-download pages, counterfeit macOS tools, cracked-application lures, malvertising, SEO-poisoning and AI-themed social-engineering campaigns, compromised websites, and ClickFix-style instructions that persuade victims to run Terminal commands. Login Items persistence has also been reported. Infrastructure overlap has been reported with ShadowSyndicate-linked activity, but this does not establish definitive operational ownership or attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We found connections between ShadowSyndicate infrastructure and Amos Stealer infrastructure (moderate confidence)
29 distinct techniques documented for this family, organized by ATT&CK tactic.
ClearFake is a malicious JavaScript framework deployed on compromised websites to deliver malware through the drive-by download technique.
An active malware distribution campaign abusing two prominent AI platforms Hugging Face and ClawHub to deliver trojans, cryptominers, and infostealers disguised as legitimate AI tools and agent extensions. The campaign marks a significant evolution in supply chain attacks, shifting from traditional software repositories to trusted AI ecosystems.
Shown above: Text from the fake Brew page pasted into a terminal Window.
The AMOS Stealer is a macOS malware known for its data theft capabilities, often delivered via an encrypted osascript (AppleScript) payload.
Once the script is downloaded, it automatically launches an AppleScript command using the zsh terminal shell to begin collecting data.
The sidebar provided two follow-on options: ClickFix-style instructions and a download option, both intended to download and execute malicious code.
This involved a Google Doc featuring a custom Google Apps Script sidebar designed to guide them through the execution of malware.
AMOS has been distributed through ClickFix campaigns, malicious advertisements, and websites offering cracked versions of popular software. These sites use fake installation instructions, such as a supposed macOS toolkit, to trick users into installing the malware.
MacOS maintains a list of applications that should be automatically opened when a user logs in. This list is stored in the com.apple.loginwindow preferences domain under the key AutoLaunchedApplicationDictionary ... it is the programmatic equivalent of a user manually adding an app to their “Login Items” in System Settings.
MacOS maintains a list of applications that should be automatically opened when a user logs in. This list is stored in the com.apple.loginwindow preferences domain under the key AutoLaunchedApplicationDictionary ... it is the programmatic equivalent of a user manually adding an app to their “Login Items” in System Settings.
For Windows targets, payloads were detected as trojans packed with VMProtect... A second Windows payload used a 30-byte XOR key to decrypt strings at runtime... The FAKESECURITY campaign used a batch script (CDC1.bat) containing an encoded PowerShell blob...
This analysis examines an AMOS Stealer infection ... delivered through a page promoting a fake “macOS toolkit.”
After a successful upload, Amos Stealer runs the cleanup commands ( rm -f /tmp/osalogging.zip and rm -rf /tmp/sync ) to erase its presence.
AMOS Stealer often employs anti-VM techniques to evade analysis in sandboxed environments, typically by querying system information to detect virtualization signatures like QEMU or VMware.
Prompts for the system password if needed, using a deceptive dialog disguised as a legitimate "System Preferences" request.
It then collects stored passwords, session cookies, and autofill form information from Google Chrome and Microsoft Edge browsers.
It steals system information, credentials, and sensitive data from web browsers, cryptocurrency wallets, and other applications.
It steals system information, credentials, and sensitive data from web browsers, cryptocurrency wallets, and other applications.
Prompts for the system password if needed, using a deceptive dialog disguised as a legitimate "System Preferences" request.
67 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS information stealer that collects system information, credentials, and sensitive data from web browsers, cryptocurrency wallets, and other applications. It has been distributed through ClickFix campaigns, malicious advertisements, and fake/cracked-software websites that use fraudulent installation instructions.
A stealer referenced as part of prior AI-hosted ClickFix campaigns, not the main malware in this report.
A macOS stealer referenced as lineage/comparison for MacSync. The content says MacSync shares AMOS-style AppleScript execution, fake password prompts validated with dscl authonly, Safe Storage key theft, browser and wallet collection, and poisoned-search delivery patterns.
A macOS-focused information stealer used in financially motivated campaigns. It steals browser passwords, session cookies, autofill data, copies the macOS Keychain database, collects developer configuration files and keys, compresses stolen data, exfiltrates it to attacker-controlled infrastructure via curl, and removes artifacts afterward.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.