Cookie Spider is a financially motivated cybercrime actor associated with the development and rental of Atomic macOS Stealer (AMOS) and its newer SHAMOS variant under a malware-as-a-service model. The group is tracked as an eCrime operator focused on macOS users, with particular emphasis on credential theft and cryptocurrency theft. Cookie Spider’s operations have used malvertising, fake support pages, and socially engineered terminal one-liners to induce user execution on macOS. The actor has also been linked to malicious software distribution through deceptive repositories and AI-agent ecosystem abuse, including delivery paths involving OpenClaw-related malicious skills and comments that trick users into executing commands. Observed tradecraft includes command obfuscation, anti-virtualization checks, AppleScript-based reconnaissance and collection, staged payload delivery, and attempts to bypass macOS Gatekeeper protections. The group’s malware targets browser credentials, cookies, autofill data, local storage, Safari data, Firefox-family data, macOS Keychain material, and Apple Notes, while also extensively harvesting cryptocurrency wallet data from browser extensions and desktop wallet applications. More recent AMOS activity attributed to Cookie Spider expanded beyond classic infostealing into broader crypto-focused intrusion activity, including replacement of legitimate wallet software with trojanized clones designed to phish BIP39 recovery phrases and deployment of a persistent backdoor for long-term remote access and tasking. Cookie Spider has demonstrated persistence and post-compromise capability on infected macOS systems, including launch daemon abuse and installation of a backdoor that supports registration, task polling, arbitrary command execution, repeated execution, heartbeat signaling, and self-deletion. The actor’s tooling also shows defense-evasion features such as multilayer payload encryption and execution methods intended to reduce visibility into decrypted payloads. Known associated malware and activity names include Atomic macOS Stealer, AMOS, SHAMOS, and OpenClaw-related malicious delivery activity. Cookie Spider is best characterized as a macOS-focused MaaS operator serving the cybercrime ecosystem, with strong specialization in credential theft, session theft, exfiltration, persistence, and cryptocurrency-focused fraud.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
47 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operating and rapidly evolving the AMOS macOS stealer campaign, including credential theft, browser and wallet data theft, replacement of legitimate Ledger/Trezor/Exodus apps with trojanized clones to phish BIP39 seed phrases, and deployment of the kito persistence backdoor via a three-tier C2 infrastructure.
Cybercrime actor associated with developing and renting Atomic Stealer, a macOS information stealer delivered via malicious OpenClaw/ClawHub skills.
MaaS operator behind a variant of Atomic macOS Stealer (SHAMOS), delivered via ClickFix-style social engineering to run terminal commands that download and execute the stealer and additional payloads (e.g., spoofed wallet app, botnet module).
COOKIE SPIDER is a cybercriminal group responsible for developing and deploying macOS infostealers (AMOS/SHAMOS) using social engineering and ClickFix techniques to compromise users.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.