2026-08-02
- threat intel
Atomic MacOS (AMOS) stealer infection
A researcher documented an Atomic MacOS (AMOS) stealer infection acquired on July 31, 2026 from a deceptive webpage offering a fake macOS toolkit. The attack distributed malware through a social engineering chain: a malicious webpage directed users to paste a command into Terminal that downloaded shell scripts, which in turn retrieved and installed the AMOS stealer binary that persisted across multiple directories. The analysis includes indicators of compromise, file hashes, command and control server addresses, and network traffic patterns revealing the malware's staged infection process and data exfiltration activities.
Why it matters: macOS administrators and security teams need these indicators of compromise to detect AMOS stealer infections in their environments; the malware targets credentials, browser data, wallets, and messenger applications, making it a direct threat to organizational and personal data security.