AMOS Stealer, also known as Atomic Stealer or Atomic macOS Stealer, is a macOS information-stealing malware family that emerged in 2023. It is sold as malware-as-a-service through Telegram and underground forums and is maintained by a developer using the alias ping3r. Financially motivated operators use it against individuals and organizations, including users handling cryptocurrency and sensitive corporate or developer credentials.
AMOS collects saved browser passwords, cookies, autofill information, browsing history, macOS Keychain data, cryptocurrency wallet files and keys, Telegram session data, selected documents, and system information. It targets Chromium-based browsers and Firefox, among other applications. Fake system authentication dialogs solicit the victim's account password to facilitate credential access. Observed implementations execute encrypted or encoded AppleScript through native macOS utilities, archive collected information, and upload it to attacker-controlled infrastructure. Some implementations retry failed uploads and remove temporary collection artifacts afterward. Analyzed samples include universal Mach-O binaries supporting Intel and Apple silicon systems. Evasion behaviors include virtual-machine checks, concealed Terminal activity, payload obfuscation, and social engineering to bypass Gatekeeper protections. Persistence has been observed through macOS Login Items and launch agents.
Distribution includes phishing, deceptive software downloads, cracked applications, malicious advertisements, and fake-update campaigns such as ClearFake. ClickFix campaigns impersonate software installation guides or troubleshooting instructions and persuade victims to paste malicious commands into Terminal. Lures have impersonated Claude Code and macOS utilities, abused shared AI conversations, and redirected users through altered GitHub download links. Malicious OpenClaw skills distributed through ClawHub have also delivered AMOS.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
MITRE CONTEXT — Exploits Vulnerabilities: CVE-2021-4436; Threat Names: AMOS Stealer.
MITRE CONTEXT — Exploits Vulnerabilities: CVE-2025-0282; Threat Names: AMOS Stealer.
MITRE CONTEXT — Exploits Vulnerabilities: CVE-2024-3400; Threat Names: AMOS Stealer.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We found connections between ShadowSyndicate infrastructure and Amos Stealer infrastructure (moderate confidence)
35 distinct techniques documented for this family, organized by ATT&CK tactic.
Shown above: Text from the fake Brew page pasted into a terminal Window.
Once the script is downloaded, it automatically launches an AppleScript command using the zsh terminal shell to begin collecting data.
The sidebar provided two follow-on options: ClickFix-style instructions and a download option, both intended to download and execute malicious code.
This involved a Google Doc featuring a custom Google Apps Script sidebar designed to guide them through the execution of malware.
AMOS has been distributed through ClickFix campaigns, malicious advertisements, and websites offering cracked versions of popular software. These sites use fake installation instructions, such as a supposed macOS toolkit, to trick users into installing the malware.
MITRE Technique Names: Obfuscated Files or Information; MITRE Technique IDs: T1027
After a successful upload, Amos Stealer runs the cleanup commands ( rm -f /tmp/osalogging.zip and rm -rf /tmp/sync ) to erase its presence.
MITRE Technique Names: Local Account; MITRE Technique IDs: T1078.003
AMOS Stealer often employs anti-VM techniques to evade analysis in sandboxed environments, typically by querying system information to detect virtualization signatures like QEMU or VMware.
Stealth and persistence Hides its execution by setting the Terminal window to invisible.
MITRE Technique Names: Hidden File System; MITRE Technique IDs: T1564.005
Prompts for the system password if needed, using a deceptive dialog disguised as a legitimate "System Preferences" request.
It then collects stored passwords, session cookies, and autofill form information from Google Chrome and Microsoft Edge browsers.
MITRE Technique Names: System Information Discovery; gathers system profiling information, such as macOS version
MITRE Technique Names: Local Accounts; MITRE Technique IDs: T1087.001
MITRE Technique Names: Peripheral Device Discovery; MITRE Technique IDs: T1120
AMOS Stealer often employs anti-VM techniques to evade analysis in sandboxed environments, typically by querying system information to detect virtualization signatures like QEMU or VMware.
It steals system information, credentials, and sensitive data from web browsers, cryptocurrency wallets, and other applications.
Prompts for the system password if needed, using a deceptive dialog disguised as a legitimate "System Preferences" request.
68 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS information stealer delivered through a malicious advertisement and website impersonating Claude Code. The documented infection uses ClickFix-style instructions to persuade the victim to paste a script into macOS Terminal. The malware subsequently displays password and permission requests.
A macOS stealer mentioned only for comparison. The author has not identified the malware delivered by the MacFinger ClickFix campaign and states that it does not appear to be AMOS Stealer. MacFinger is presented as a campaign name, not an identified malware family.
A macOS information stealer that collects system information, credentials, and sensitive data from web browsers, cryptocurrency wallets, and other applications. It has been distributed through ClickFix campaigns, malicious advertisements, and fake/cracked-software websites that use fraudulent installation instructions.
A stealer referenced as part of prior AI-hosted ClickFix campaigns, not the main malware in this report.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.