Atomic macOS Stealer, also widely known as AMOS, is a macOS-focused information-stealing malware family commonly sold as malware-as-a-service in criminal ecosystems. It is designed to steal credentials and other sensitive data from Apple systems, with collection logic targeting browser passwords, cookies, autofill data, keychain material, cryptocurrency wallet data, Telegram Desktop data, SSH and developer-related files, and selected user documents. Reported variants also gather host profiling information and package stolen data for exfiltration using native macOS utilities and AppleScript-based workflows.
AMOS is frequently delivered through social engineering rather than software exploitation. Observed delivery themes include deceptive software downloads, fake websites, cracked-application lures, malvertising, poisoned search results, weaponized AI or chat-sharing pages, and ClickFix-style terminal-command lures that trick users into pasting and executing shell commands. ClearFake activity has also been reported delivering AMOS to macOS users. Infection chains commonly rely on curl, zsh, osascript, and other built-in macOS components to download and execute payloads while minimizing on-disk artifacts.
Technical reporting shows AMOS often uses encrypted or obfuscated AppleScript payloads executed in memory, anti-analysis checks such as virtualization detection, and user-interface deception including fake system prompts to obtain passwords or additional permissions. Documented theft targets include Chromium-based browsers, Firefox-family browsers, Safari artifacts, cryptocurrency wallets, Telegram Desktop, and sensitive files from common user directories. Some campaigns also sought access to the macOS Keychain and developer or cloud-related material such as SSH and Kubernetes files.
Persistence has been observed through mechanisms including Login Items and shell-profile modification, allowing the malware to relaunch after user interaction or subsequent logins. AMOS activity has also been associated with broader criminal delivery ecosystems and infrastructure overlaps involving other malware families and bulletproof hosting environments. Reporting has linked AMOS distribution to campaigns abusing trusted platforms and brands, including AI-themed lures and developer-oriented malvertising, underscoring its role as a financially motivated macOS infostealer aimed at credential theft, cryptocurrency theft, and follow-on compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We found connections between ShadowSyndicate infrastructure and Amos Stealer infrastructure (moderate confidence)
28 distinct techniques documented for this family, organized by ATT&CK tactic.
ClearFake is a malicious JavaScript framework deployed on compromised websites to deliver malware through the drive-by download technique.
An active malware distribution campaign abusing two prominent AI platforms Hugging Face and ClawHub to deliver trojans, cryptominers, and infostealers disguised as legitimate AI tools and agent extensions. The campaign marks a significant evolution in supply chain attacks, shifting from traditional software repositories to trusted AI ecosystems.
Shown above: Text from the fake Brew page pasted into a terminal Window.
The AMOS Stealer is a macOS malware known for its data theft capabilities, often delivered via an encrypted osascript (AppleScript) payload.
Once the script is downloaded, it automatically launches an AppleScript command using the zsh terminal shell to begin collecting data.
MacOS maintains a list of applications that should be automatically opened when a user logs in. This list is stored in the com.apple.loginwindow preferences domain under the key AutoLaunchedApplicationDictionary ... it is the programmatic equivalent of a user manually adding an app to their “Login Items” in System Settings.
MacOS maintains a list of applications that should be automatically opened when a user logs in. This list is stored in the com.apple.loginwindow preferences domain under the key AutoLaunchedApplicationDictionary ... it is the programmatic equivalent of a user manually adding an app to their “Login Items” in System Settings.
For Windows targets, payloads were detected as trojans packed with VMProtect... A second Windows payload used a 30-byte XOR key to decrypt strings at runtime... The FAKESECURITY campaign used a batch script (CDC1.bat) containing an encoded PowerShell blob...
After a successful upload, Amos Stealer runs the cleanup commands ( rm -f /tmp/osalogging.zip and rm -rf /tmp/sync ) to erase its presence.
AMOS Stealer often employs anti-VM techniques to evade analysis in sandboxed environments, typically by querying system information to detect virtualization signatures like QEMU or VMware.
Prompts for the system password if needed, using a deceptive dialog disguised as a legitimate "System Preferences" request.
It then collects stored passwords, session cookies, and autofill form information from Google Chrome and Microsoft Edge browsers.
System Information : Captures hardware, software, and display details using system_profiler .
File Grabber : Collects files with specific extensions (e.g., .txt, .pdf, .docx, .wallet, .key) from Desktop, Documents, and Downloads folders
Prompts for the system password if needed, using a deceptive dialog disguised as a legitimate "System Preferences" request.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS stealer referenced as lineage/comparison for MacSync. The content says MacSync shares AMOS-style AppleScript execution, fake password prompts validated with dscl authonly, Safe Storage key theft, browser and wallet collection, and poisoned-search delivery patterns.
A macOS-focused information stealer used in financially motivated campaigns. It steals browser passwords, session cookies, autofill data, copies the macOS Keychain database, collects developer configuration files and keys, compresses stolen data, exfiltrates it to attacker-controlled infrastructure via curl, and removes artifacts afterward.
A macOS-focused infostealer delivered in this campaign via malicious AI platform content; it is described as being sold as malware-as-a-service through Telegram and underground forums.
A macOS-focused infostealer distributed via malicious OpenClaw skills in this campaign. It is delivered through staged shell scripts that download and execute the payload from attacker-controlled infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.