Atomic macOS Stealer (AMOS) was delivered through a fraudulent macOS toolkit installation site, getmacouscloud[.]com, that instructed victims to paste malicious commands into Terminal. The commands retrieved Zsh scripts that installed persistent AMOS Mach-O payloads, then prompted users for their macOS password and requested system permissions to facilitate collection.
The stealer targets system information, credentials and Keychain data, browser and messenger artifacts, cryptocurrency-wallet data, and locally accessible files, staging collected content in /tmp/out.zip. In the observed infection, AMOS sent data to 161.35.146[.]120 via HTTP POST requests whose URL stages exposed the collection workflow; defenders should prioritize behavioral detection because its infrastructure, filenames, paths, hashes, and C2 addresses change rapidly while its social-engineering delivery and data-theft patterns remain consistent.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
The analyzed infection staged collected data in /tmp/out.zip, including browser, messenger, wallet, cloud-service, and local-file data, then primarily sent HTTP POST requests to C2 server 161.35.146[.]120. Its request paths exposed collection stages including boot, init_session, credentials, browsers, wallets, messengers, and local_data.
A laboratory-generated AMOS infection was observed being delivered through getmacouscloud[.]com, a fraudulent macOS toolkit-installation page that instructed users to paste a malicious command into Terminal. The command retrieved scripts from ferncore13[.]com and installed persistent AMOS components while seeking user credentials and macOS permissions.
A separate AMOS infection was observed using C2 server 188.166.78[.]138. Its C2 URL patterns remained similar to those seen in other AMOS activity.
Atomic macOS Stealer (AMOS), a macOS-focused information stealer, was advertised on Telegram as early as April 2024.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.