Atomic macOS (AMOS) Stealer Activity
An analysis of Atomic macOS (AMOS) stealer infections from early August 2026 reveals this information stealer targeting macOS systems has been advertised since April 2024. AMOS exfiltrates system information, login credentials, and sensitive data from web browsers and cryptocurrency wallets. Distribution methods include ClickFix campaigns, malicious advertisements, and fake cracked software sites offering macOS toolkits. The examined infection chain begins with malicious instructions on getmacouscloud[.]com, leading to execution of a Zsh script that retrieves and installs Mach-O binaries establishing persistence in system directories. The malware collects data from various applications including Binance, TonKeeper, Telegram, AWS, Docker, and FileZilla, compressing it into an out.zip file before exfiltrating to command and control servers. Post-infection traffic consists of HTTP POST requests with specific stage parameters indicating collected data types. The malware demonstrates active development with con...
AI Analysis
Technical Summary
AMOS stealer is a macOS information stealer malware first advertised in April 2024 and actively evolving as of August 2026. It is distributed through malicious websites that trick users into running terminal commands that download and execute payloads. The infection installs Mach-O binaries and shell scripts in user Library directories, requiring administrative password input and requesting permissions to control Finder, access Desktop and Documents folders, and control the Notes application. It collects data from various applications, including cryptocurrency wallets and messaging apps, compresses the data into an archive, and exfiltrates it via HTTP POST requests to frequently changing C2 servers. Indicators such as domains, IPs, filenames, and hashes change often, indicating ongoing development and evasion efforts. Palo Alto Networks products provide detection capabilities for known indicators.
Potential Impact
AMOS stealer compromises macOS systems by stealing sensitive user data including system information, login credentials, browser data, cryptocurrency wallet contents, and messaging data. It requires user interaction to execute and administrative privileges to install. The malware exfiltrates collected data to attacker-controlled servers, potentially leading to credential theft, financial loss, and privacy breaches. The malware's active development and frequent indicator changes complicate detection and response efforts.
Mitigation Recommendations
No official patch is applicable as this is malware infection rather than a software vulnerability. Mitigation focuses on user education to avoid running untrusted terminal commands and downloading software from unverified sources. Endpoint protection solutions such as Palo Alto Networks Advanced URL Filtering and Advanced DNS Security can identify and block known malicious domains and URLs associated with AMOS stealer. Monitoring for unusual terminal activity and restricting administrative privileges can reduce risk. Users should be cautious of prompts requesting passwords and permissions during terminal operations.
Indicators of Compromise
- domain: grove-89.com
- domain: getmacouscloud.com
- domain: ferncore13.com
- hash: 71781ad8adefb499aee9bcbe1a166e69ccc37a47066682f617d65c76d8cde88c
- hash: 7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ffd3d1c154d40d7ca3a
- hash: a598fcdcd49247312861ff90c16cb4a5d49fede6072e30e7416dd276668fa2a9
- hash: 6bfcdb4920383375b7e519918df7eb4db751b974b5571a15ce66b82478012620
- hash: 4504006d1911057be42435d4625f03d83c4d0b7b6898d14beb9cdeba6cf667b9
- hash: 121cc0f6c933f928273a8d259262e3bd
- hash: 3106cffb9da7380fcc0237e8fde0efa0
- hash: 65334575232f8d94fde18e89af393212
- hash: e634d35d6ae98935c51de5a23a92e965
- hash: 2849fe272d6edfdf75c1169102ea7a33d224eb7b
- hash: 2c78ad15bec38dd235f1a0f91a8ec71ecdf2701b
- hash: 65b02a832483a5fa367d96c36c56372722e752cc
- hash: 739afb0e43501a8aa6e4322fafb6841a880f0271
- hash: 608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688
Atomic macOS (AMOS) Stealer Activity
Description
An analysis of Atomic macOS (AMOS) stealer infections from early August 2026 reveals this information stealer targeting macOS systems has been advertised since April 2024. AMOS exfiltrates system information, login credentials, and sensitive data from web browsers and cryptocurrency wallets. Distribution methods include ClickFix campaigns, malicious advertisements, and fake cracked software sites offering macOS toolkits. The examined infection chain begins with malicious instructions on getmacouscloud[.]com, leading to execution of a Zsh script that retrieves and installs Mach-O binaries establishing persistence in system directories. The malware collects data from various applications including Binance, TonKeeper, Telegram, AWS, Docker, and FileZilla, compressing it into an out.zip file before exfiltrating to command and control servers. Post-infection traffic consists of HTTP POST requests with specific stage parameters indicating collected data types. The malware demonstrates active development with con...
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
AMOS stealer is a macOS information stealer malware first advertised in April 2024 and actively evolving as of August 2026. It is distributed through malicious websites that trick users into running terminal commands that download and execute payloads. The infection installs Mach-O binaries and shell scripts in user Library directories, requiring administrative password input and requesting permissions to control Finder, access Desktop and Documents folders, and control the Notes application. It collects data from various applications, including cryptocurrency wallets and messaging apps, compresses the data into an archive, and exfiltrates it via HTTP POST requests to frequently changing C2 servers. Indicators such as domains, IPs, filenames, and hashes change often, indicating ongoing development and evasion efforts. Palo Alto Networks products provide detection capabilities for known indicators.
Potential Impact
AMOS stealer compromises macOS systems by stealing sensitive user data including system information, login credentials, browser data, cryptocurrency wallet contents, and messaging data. It requires user interaction to execute and administrative privileges to install. The malware exfiltrates collected data to attacker-controlled servers, potentially leading to credential theft, financial loss, and privacy breaches. The malware's active development and frequent indicator changes complicate detection and response efforts.
Defensive Guidance
No official patch is applicable as this is malware infection rather than a software vulnerability. Mitigation focuses on user education to avoid running untrusted terminal commands and downloading software from unverified sources. Endpoint protection solutions such as Palo Alto Networks Advanced URL Filtering and Advanced DNS Security can identify and block known malicious domains and URLs associated with AMOS stealer. Monitoring for unusual terminal activity and restricting administrative privileges can reduce risk. Users should be cautious of prompts requesting passwords and permissions during terminal operations.
Technical Details
- Classification
- {"confidence":0.88,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/","fetched":true,"fetchedAt":"2026-09-16T10:10:42.850Z","wordCount":2003}
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaingrove-89.com | — | |
domaingetmacouscloud.com | — | |
domainferncore13.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash71781ad8adefb499aee9bcbe1a166e69ccc37a47066682f617d65c76d8cde88c | — | |
hash7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ffd3d1c154d40d7ca3a | — | |
hasha598fcdcd49247312861ff90c16cb4a5d49fede6072e30e7416dd276668fa2a9 | — | |
hash6bfcdb4920383375b7e519918df7eb4db751b974b5571a15ce66b82478012620 | — | |
hash4504006d1911057be42435d4625f03d83c4d0b7b6898d14beb9cdeba6cf667b9 | — | |
hash121cc0f6c933f928273a8d259262e3bd | — | |
hash3106cffb9da7380fcc0237e8fde0efa0 | — | |
hash65334575232f8d94fde18e89af393212 | — | |
hashe634d35d6ae98935c51de5a23a92e965 | — | |
hash2849fe272d6edfdf75c1169102ea7a33d224eb7b | — | |
hash2c78ad15bec38dd235f1a0f91a8ec71ecdf2701b | — | |
hash65b02a832483a5fa367d96c36c56372722e752cc | — | |
hash739afb0e43501a8aa6e4322fafb6841a880f0271 | — | |
hash608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688 | — |
Threat ID: 6aaa6b2255bf5e2cf555c9e5
Added to database: 09/16/2026, 10:10:42 UTC
Last enriched: 09/16/2026, 10:10:46 UTC
Last updated: 09/17/2026, 02:01:47 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.