Atomic Stealer, also known as AMOS, is a macOS-focused information stealer offered through a malware-as-a-service model and widely used in criminal campaigns targeting Apple users. It is designed to harvest browser credentials, stored passwords, session cookies, cryptocurrency wallet data, keychain material, authentication stores, and other sensitive files from infected systems, then exfiltrate the collected data to operator-controlled infrastructure.
The malware has been distributed through multiple social-engineering channels, including malvertising, fake software download pages, cracked-software themed sites, and ClickFix-style lures that instruct victims to paste attacker-supplied commands into Terminal or Script Editor. Recent campaigns have used counterfeit GitHub-themed download pages and large clusters of look-alike domains with server-side fingerprinting to selectively expose the lure only to visitors that appear to be genuine macOS users, reducing visibility to scanners and researchers.
On execution, Atomic Stealer commonly prompts the victim for the macOS system password to unlock additional protected data sources. Reported theft objectives include browser data, keychain data, cryptocurrency wallets, authentication material, and sensitive user files. Operators have also promoted features aimed at abusing stolen browser cookies and session material for account access. The family has undergone active development, including updates that introduced payload and string encryption to hinder static detection. Reporting in 2025 also indicated the family gained an embedded backdoor capability, showing evolution beyond straightforward data theft.
Atomic Stealer has been observed alongside other macOS stealers such as MacSync in shared lure infrastructure and broader ClickFix operations. It has been delivered in campaigns impersonating well-known software brands and through infrastructure that selectively stages payloads after browser and environment profiling. The malware remains one of the most recognizable macOS infostealer families in the criminal ecosystem and is a persistent threat to both individual and business users of macOS.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
The campaign coincides with the disclosure of a high-severity OpenClaw vulnerability (CVE-2026-25253) that enables one-click remote code execution through token exfiltration and WebSocket hijacking. Although patched in late January 2026, the flaw points to the platform’s growing attack surface.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A separate skill called omnicogg embedded the AMOS malware dropper inside a README.md file, then padded it with 22 MB of junk characters to exceed file size limits that most scanning pipelines enforce.
The campaign is infecting Mac devices with the Atomic macOS Stealer (AMOS) infostealer, which steals browser credentials, cryptocurrency wallet data, Keychain data, messaging app information, and user documents.
Diversified Malware Toolkit: Crazy Evil uses advanced tools like Stealc and AMOS for Windows and macOS, ensuring widespread compromise.
Odyssey isn’t original work. It’s a direct rebrand of Poseidon Stealer, which itself was forked from Atomic macOS Stealer (AMOS).
Odyssey isn’t original work. It’s a direct rebrand of Poseidon Stealer, which itself was forked from Atomic macOS Stealer (AMOS).
Two new AMOS (Atomic macOS Stealer) samples uploaded to MalwareBazaar reveal a significant evolution of the macOS stealer family.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
attackers exploited trusted digital supply chain infrastructure used by victims in H1 2026. This included threat actors in April hijacking Axios to spread remote access trojans (RATs).
This attack used a browser-triggered workflow to launch Script Editor, which is where the user is encouraged to enter commands.
it appears that around December 17 Atomic Stealer had changed some of its code to hide certain strings that were previously used for detection and identifying its command and control server
It then phishes the account password via a fake System Preferences prompt, validating each guess in real time against macOS’s Open Directory service until a correct one is entered.
Stealing browser cookies can sometimes be even better than having the victim’s password, enabling authentication into accounts via session tokens
Further scripts download and launch AMOS, which can take browser credentials, stored passwords, cryptocurrency wallet data, authentication material, and sensitive files before sending them out.
It then phishes the account password via a fake System Preferences prompt, validating each guess in real time against macOS’s Open Directory service until a correct one is entered.
After assigning the Build ID, the malware connects to a set of URLs ... and transmits the collected data
594 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a similar macOS stealer for comparison only.
Mentioned for comparison as another stealer with similar objectives.
A stealer family mentioned as using the same fake GitHub lure template infrastructure as AmnesiaStealer.
Autre famille de stealer macOS mentionnée comme ayant utilisé le même template de page GitHub leurre que celui observé pour AmnesiaStealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.