Atomic macOS Stealer (AMOS), also known as Atomic Stealer, is a macOS information-stealing malware family that emerged in 2023 and is distributed as malware-as-a-service. It targets individuals and organizations using Apple devices, with payloads available for both Apple Silicon and Intel-based Macs. Its principal objectives are credential theft, authenticated-session theft, and cryptocurrency theft.
AMOS collects browser-stored passwords, cookies, browsing history, macOS Keychain contents, cryptocurrency-wallet data, private keys, and seed phrases. Observed campaigns also target password-manager exports, SSH and GPG keys, developer and cloud credentials, system information, and sensitive personal or proprietary files. Stolen information is exfiltrated to attacker-controlled servers. Its theft of cookies and authentication tokens enables attackers to reuse authenticated sessions; AMOS infections have been associated with compromised Claude accounts. Some versions support launch-agent persistence and configuration-driven collection.
Distribution relies heavily on social engineering, including phishing, deceptive software-download pages, malicious advertisements, and ClickFix prompts impersonating CAPTCHA verification or troubleshooting instructions. Campaigns have delivered AMOS through compromised WordPress websites, SEO-poisoned shared ChatGPT and Grok conversations, advertisements impersonating Claude Code, and malicious third-party AI-agent skills. Meowsterio is among the malware-distribution operations observed delivering AMOS to macOS users. Infection chains can select architecture-specific payloads, remove macOS quarantine attributes, apply ad-hoc signatures, and conceal execution in the background.
AMOS has also served as a codebase for other macOS stealer families and variants, including Odyssey Stealer, SHAMOS, Banshee Stealer, and Cthulhu Stealer. Related families can have substantially different capabilities and should not be treated as interchangeable with AMOS.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
The campaign coincides with the disclosure of a high-severity OpenClaw vulnerability (CVE-2026-25253) that enables one-click remote code execution through token exfiltration and WebSocket hijacking. Although patched in late January 2026, the flaw points to the platform’s growing attack surface.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
One of the most notable examples of this shift is Atomic macOS Stealer (AMOS), a specialized malware family designed to steal sensitive data directly from Apple users.
A separate skill called omnicogg embedded the AMOS malware dropper inside a README.md file, then padded it with 22 MB of junk characters to exceed file size limits that most scanning pipelines enforce.
The campaign is infecting Mac devices with the Atomic macOS Stealer (AMOS) infostealer, which steals browser credentials, cryptocurrency wallet data, Keychain data, messaging app information, and user documents.
Diversified Malware Toolkit: Crazy Evil uses advanced tools like Stealc and AMOS for Windows and macOS, ensuring widespread compromise.
Odyssey isn’t original work. It’s a direct rebrand of Poseidon Stealer, which itself was forked from Atomic macOS Stealer (AMOS).
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The official HBO Max Reddit account was reportedly compromised and used in a malvertising campaign... The compromised account published 108 advertisements... promoting fake downloads.
MITRE Technique Names: Local Account; MITRE Technique IDs: T1078.003
The fake Mac installation guide instructed the user to paste a curl command into Terminal, triggering a six-stage chain. ChatGPT and Grok pages similarly provided ClickFix-style terminal commands.
The sites instructed visitors to open Terminal on their Mac or, on Windows, the Run dialog or PowerShell, and paste in a command. This is the hallmark of a growing social engineering technique known as ClickFix.
Victims clicked Bing sponsored ads or top-ranked search results that led to malicious Claude Artifacts, claude.ai/share pages, and shared ChatGPT/Grok conversations.
The official HBO Max Reddit account was reportedly compromised and used in a malvertising campaign... The compromised account published 108 advertisements... promoting fake downloads.
The official HBO Max Reddit account was reportedly compromised and used in a malvertising campaign... The compromised account published 108 advertisements... promoting fake downloads.
MITRE Technique Names: Obfuscated Files or Information; MITRE Technique IDs: T1027
The official HBO Max Reddit account was reportedly compromised and used in a malvertising campaign... The compromised account published 108 advertisements... promoting fake downloads.
MITRE Technique Names: System Information Discovery; gathers system profiling information, such as macOS version
MITRE Technique Names: Local Accounts; MITRE Technique IDs: T1087.001
737 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a comparison: a stealer with cryptocurrency wallet application-swapping capabilities involving Ledger and Trezor. No operational connection to PamStealer is established.
A macOS information stealer associated with an infection delivered through a malicious advertisement impersonating Claude Code. The supplied content provides no further technical details.
Information stealer mentioned in a background example of prior AI-platform abuse.
An information stealer reportedly delivered through malicious OpenClaw ClawHub skills in the ClawHavoc supply-chain campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.