CYBERSECURITYTRACKER
TRACKING6,767 stories in this site build1,408 vulnerability news stories in this site build
Permanent story citation

Atomic MacOS (AMOS) stealer infection

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3688

As cited

Copy frozen at (site build).

threat intel

Atomic MacOS (AMOS) stealer infection

A researcher documented an Atomic MacOS (AMOS) stealer infection acquired on July 31, 2026 from a deceptive webpage offering a fake macOS toolkit. The attack distributed malware through a social engineering chain: a malicious webpage directed users to paste a command into Terminal that downloaded shell scripts, which in turn retrieved and installed the AMOS stealer binary that persisted across multiple directories. The analysis includes indicators of compromise, file hashes, command and control server addresses, and network traffic patterns revealing the malware's staged infection process and data exfiltration activities.

Why it matters: macOS administrators and security teams need these indicators of compromise to detect AMOS stealer infections in their environments; the malware targets credentials, browser data, wallets, and messenger applications, making it a direct threat to organizational and personal data security.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Atomic MacOS (AMOS) stealer infection

A researcher documented an Atomic MacOS (AMOS) stealer infection acquired on July 31, 2026 from a deceptive webpage offering a fake macOS toolkit. The attack distributed malware through a social engineering chain: a malicious webpage directed users to paste a command into Terminal that downloaded shell scripts, which in turn retrieved and installed the AMOS stealer binary that persisted across multiple directories. The analysis includes indicators of compromise, file hashes, command and control server addresses, and network traffic patterns revealing the malware's staged infection process and data exfiltration activities.

Why it matters: macOS administrators and security teams need these indicators of compromise to detect AMOS stealer infections in their environments; the malware targets credentials, browser data, wallets, and messenger applications, making it a direct threat to organizational and personal data security.

VendorsApple
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary