Last seven days
- First activity
- Jul 14, 2026
- Last activity
- Jul 14, 2026
- Feed role
- C2
- Host form
- 2 IP / 0 hostnames
Atomic macOS Stealer, commonly abbreviated AMOS, is a macOS-focused infostealer used to steal credentials, browser data, cryptocurrency wallet material, and other sensitive user information.
Profile source: Mallory opens in a new tabAtomic Stealer
Atomic macOS Stealer, commonly abbreviated AMOS, is a macOS-focused infostealer used to steal credentials, browser data, cryptocurrency wallet material, and other sensitive user information. It has been active in multiple criminal campaigns and is frequently associated with social-engineering-driven delivery, especially ClickFix-style lures that trick victims into pasting attacker-supplied commands into Terminal. AMOS has also appeared in poisoned AI chatbot conversations, malicious sponsored ads, typosquatted marketplace content, and fake utility or troubleshooting workflows targeting Mac users.
AMOS targets macOS systems, including both Intel and Apple Silicon environments through universal Mach-O payloads in some observed variants. Its collection scope commonly includes saved browser credentials, cookies, form data, session material, Apple Keychain data, Telegram session data, iCloud-related information, notes, shell history, and files from desktop and browser-based cryptocurrency wallets. Reported wallet targeting includes both software wallets and companion applications for hardware wallets. Some campaigns have also used trojanized wallet application replacements to increase theft opportunities.
Observed AMOS tradecraft includes extensive use of native macOS utilities and AppleScript, local password validation, archive creation, and HTTP-based exfiltration. Variants have been seen prompting victims with fake macOS authentication dialogs to capture the login password, querying Keychain items, collecting host profiling data, and compressing stolen material before transmission. Some AMOS-linked activity has used in-memory loaders, obfuscated shell stages, and fragmented payload reconstruction to reduce visibility. Persistence has also been documented in certain variants through LaunchAgents and fake updater components that can execute follow-on commands, extending the malware beyond pure one-time theft.
AMOS is heavily represented in campaigns aimed at cryptocurrency users, developers, and Web3 communities, but its theft scope is broader than crypto alone. It has been delivered through compromised websites, phishing-style landing pages, malicious ads, and abusive AI-agent marketplace content. Related reporting also places AMOS alongside other macOS stealers such as MacSync and SHub Stealer in broader waves of macOS ClickFix activity. The malware reflects the maturation of the macOS criminal malware ecosystem and the growing attacker focus on enterprise and consumer Mac endpoints as viable targets for credential theft, session hijacking, and financial theft.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
A separate skill called omnicogg embedded the AMOS malware dropper inside a README.md file, then padded it with 22 MB of junk characters to exceed file size limits that most scanning pipelines enforce.
The campaign is infecting Mac devices with the Atomic macOS Stealer (AMOS) infostealer, which steals browser credentials, cryptocurrency wallet data, Keychain data, messaging app information, and user documents.
Diversified Malware Toolkit: Crazy Evil uses advanced tools like Stealc and AMOS for Windows and macOS, ensuring widespread compromise.
Odyssey isnโt original work. Itโs a direct rebrand of Poseidon Stealer, which itself was forked from Atomic macOS Stealer (AMOS).
Odyssey isnโt original work. Itโs a direct rebrand of Poseidon Stealer, which itself was forked from Atomic macOS Stealer (AMOS).
Two new AMOS (Atomic macOS Stealer) samples uploaded to MalwareBazaar reveal a significant evolution of the macOS stealer family.
Exploited software
MITRE ATT&CK
Reporting
While ClickFix has historically targeted Windows users, researchers recently observed its delivery of Atomic Stealer malware on macOS systems, leading experts to warn that โmacOS must no longer be treated as lower risk.โ
This shift mirrors recent trends where Mac endpoints are targeted directly via the web, such as the Atomic Stealer ClickFix attack.
Microsoft documented the same dscl validation in SHub Stealer in May, alongside AMOS and MacSync in the same wave of macOS ClickFix campaigns.
Although the macOS threat landscape has grown considerably in recent years, with malware like Atomic Stealer (AMOS), Banshee Stealer, Poseidon, Cuckoo, Cthulhu Stealer and MacStealer...
Hackers Used EvilTokens, ClickFix Campaign to Attack Claude Code Users with AMOS Stealer
AMOS killed Ledger Live and dropped a trojanized clone in /Applications demanding the 24 words.
As described by Huntress researchers, Atomic MacOS Stealer is being distributed through poisoned AI chatbot conversations that lead unwitting victims to malicious websites and payloads.
Static reverse engineering indicates that the sample is a macOS information stealer whose behavioral characteristics are highly consistent with variants of AMOS (Atomic macOS Stealer).
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.