Atomic macOS Stealer (AMOS) is a macOS information stealer that targets browser-resident data, locally stored credentials, cryptocurrency wallets, and cryptocurrency-browser extensions. It can collect saved browser passwords, active session cookies, application credentials, and browser encryption material obtained through macOS Keychain access. Stolen authenticated browser sessions can be replayed to hijack online accounts without a new password or MFA challenge; AMOS has been identified in theft of active Claude sessions from affected macOS systems. Some AMOS deployments, including a build referred to as NITRO, target desktop cryptocurrency-wallet applications and browser cryptocurrency extensions, use deceptive macOS dialogs to solicit administrator passwords, archive collected data, and exfiltrate it to operator infrastructure. Observed campaigns distribute AMOS through fake software-download pages, malicious advertising and SEO-poisoned results, and ClickFix-style lures that persuade users to paste commands into Terminal. Delivery chains have used staged shell scripts, obfuscation, removal of macOS download-quarantine metadata, and universal Mach-O payloads. A reported campaign also used a persistent backdoor with LaunchAgent-based execution and blockchain-based command-and-control resolution to deploy AMOS or cryptomining payloads. No conclusive attribution to a specific threat actor is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
The campaign coincides with the disclosure of a high-severity OpenClaw vulnerability (CVE-2026-25253) that enables one-click remote code execution through token exfiltration and WebSocket hijacking. Although patched in late January 2026, the flaw points to the platform’s growing attack surface.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
One of the most notable examples of this shift is Atomic macOS Stealer (AMOS), a specialized malware family designed to steal sensitive data directly from Apple users.
A separate skill called omnicogg embedded the AMOS malware dropper inside a README.md file, then padded it with 22 MB of junk characters to exceed file size limits that most scanning pipelines enforce.
The campaign is infecting Mac devices with the Atomic macOS Stealer (AMOS) infostealer, which steals browser credentials, cryptocurrency wallet data, Keychain data, messaging app information, and user documents.
Diversified Malware Toolkit: Crazy Evil uses advanced tools like Stealc and AMOS for Windows and macOS, ensuring widespread compromise.
Odyssey isn’t original work. It’s a direct rebrand of Poseidon Stealer, which itself was forked from Atomic macOS Stealer (AMOS).
Odyssey isn’t original work. It’s a direct rebrand of Poseidon Stealer, which itself was forked from Atomic macOS Stealer (AMOS).
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Bösartige Akteure ... nutzten [gestohlene Claude-Login-Sessions] dafür, auf die Konten zuzugreifen und die verfügbaren Token zu nutzen.
Once obtained, the miscreant is using the stolen information to use premium Claude services without having to pay the bill themselves.
Public skill marketplaces have already been actively abused. Between January 27 and 31, a campaign researchers named ClawHavoc flooded ClawHub with 341 malicious skills.
“The ‘Apple Support install guide’ told the victim to paste a curl command into Terminal.”
a popular social engineering technique that persuades victims to execute the infection step themselves rather than opening a malicious file
it decodes a Base64-encoded URL and downloads a script that is piped into zsh... The first stage acts as a loader that decodes and executes an embedded script
Trend Micro documented a parallel campaign in which attackers distributed the Atomic macOS Stealer infostealer through disguised OpenClaw skills. The infection mechanism was a skill with professional-looking documentation that instructed the agent to present a fake setup requirement.
It also uses xattr -c to strip the file’s extended attributes before making it executable and launching it.
Bösartige Akteure ... nutzten [gestohlene Claude-Login-Sessions] dafür, auf die Konten zuzugreifen und die verfügbaren Token zu nutzen.
« Ces programmes copient les cookies de connexion stockés dans le navigateur » ; « Un attaquant qui copie ce cookie et le rejoue depuis un autre appareil apparaît alors [...] comme la personne ayant déjà réussi cette vérification ».
Popular tools like VPNs, often used by users with limited security resources, combined with legitimate command-and-control (C2) infrastructure enables attackers to reach a far wider victim base while frustrating defenders who cannot simply block the associated endpoints.
711 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Voleur d’informations macOS employé ici pour dérober des cookies de navigateur et des mots de passe enregistrés, afin de réutiliser des sessions Claude authentifiées.
Named as one of several infostealers identified on impacted systems that can collect login cookies, application credentials, and browser passwords, enabling theft of active Claude sessions.
macOS infostealer distributed through disguised OpenClaw skills. The malicious skill used professional-looking documentation to have the agent prompt the user for their password, triggering malware installation.
A macOS information stealer identified as capable of stealing active Claude session cookies from infected computers, enabling account access without passwords and bypassing MFA and SSO.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.