Skip to main content

Atomic macOS (AMOS) Stealer Activity

0
High
Published: 09/16/2026 (09/16/2026, 12:36:20 UTC)
Source: Palo Alto Unit 42

Description

An analysis of Atomic macOS (AMOS) stealer infections from early August 2026 reveals this information stealer targeting macOS systems has been advertised since April 2024. AMOS exfiltrates system information, login credentials, and sensitive data from web browsers and cryptocurrency wallets. Distribution methods include ClickFix campaigns, malicious advertisements, and fake cracked software sites offering macOS toolkits. The examined infection chain begins with malicious instructions on getmacouscloud[.]com, leading to execution of a Zsh script that retrieves and installs Mach-O binaries establishing persistence in system directories. The malware collects data from various applications including Binance, TonKeeper, Telegram, AWS, Docker, and FileZilla, compressing it into an out.zip file before exfiltrating to command and control servers. Post-infection traffic consists of HTTP POST requests with specific stage parameters indicating collected data types. The malware demonstrates active development with con...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/16/2026, 10:10:46 UTC

Technical Analysis

AMOS stealer is a macOS information stealer malware first advertised in April 2024 and actively evolving as of August 2026. It is distributed through malicious websites that trick users into running terminal commands that download and execute payloads. The infection installs Mach-O binaries and shell scripts in user Library directories, requiring administrative password input and requesting permissions to control Finder, access Desktop and Documents folders, and control the Notes application. It collects data from various applications, including cryptocurrency wallets and messaging apps, compresses the data into an archive, and exfiltrates it via HTTP POST requests to frequently changing C2 servers. Indicators such as domains, IPs, filenames, and hashes change often, indicating ongoing development and evasion efforts. Palo Alto Networks products provide detection capabilities for known indicators.

Potential Impact

AMOS stealer compromises macOS systems by stealing sensitive user data including system information, login credentials, browser data, cryptocurrency wallet contents, and messaging data. It requires user interaction to execute and administrative privileges to install. The malware exfiltrates collected data to attacker-controlled servers, potentially leading to credential theft, financial loss, and privacy breaches. The malware's active development and frequent indicator changes complicate detection and response efforts.

Defensive Guidance

No official patch is applicable as this is malware infection rather than a software vulnerability. Mitigation focuses on user education to avoid running untrusted terminal commands and downloading software from unverified sources. Endpoint protection solutions such as Palo Alto Networks Advanced URL Filtering and Advanced DNS Security can identify and block known malicious domains and URLs associated with AMOS stealer. Monitoring for unusual terminal activity and restricting administrative privileges can reduce risk. Users should be cautious of prompts requesting passwords and permissions during terminal operations.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.88,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/","fetched":true,"fetchedAt":"2026-09-16T10:10:42.850Z","wordCount":2003}

Indicators of Compromise

Domain

ValueDescriptionCopy
domaingrove-89.com
domaingetmacouscloud.com
domainferncore13.com

Hash

ValueDescriptionCopy
hash71781ad8adefb499aee9bcbe1a166e69ccc37a47066682f617d65c76d8cde88c
hash7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ffd3d1c154d40d7ca3a
hasha598fcdcd49247312861ff90c16cb4a5d49fede6072e30e7416dd276668fa2a9
hash6bfcdb4920383375b7e519918df7eb4db751b974b5571a15ce66b82478012620
hash4504006d1911057be42435d4625f03d83c4d0b7b6898d14beb9cdeba6cf667b9
hash121cc0f6c933f928273a8d259262e3bd
hash3106cffb9da7380fcc0237e8fde0efa0
hash65334575232f8d94fde18e89af393212
hashe634d35d6ae98935c51de5a23a92e965
hash2849fe272d6edfdf75c1169102ea7a33d224eb7b
hash2c78ad15bec38dd235f1a0f91a8ec71ecdf2701b
hash65b02a832483a5fa367d96c36c56372722e752cc
hash739afb0e43501a8aa6e4322fafb6841a880f0271
hash608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688

Threat ID: 6aaa6b2255bf5e2cf555c9e5

Added to database: 09/16/2026, 10:10:42 UTC

Last enriched: 09/16/2026, 10:10:46 UTC

Last updated: 09/17/2026, 02:01:47 UTC

Views: 17

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses