An updated version of Atomic Stealer (also known as AMOS) was distributed to macOS users through a malvertising campaign that abused Google search ads and impersonated Slack. Victims who clicked the ads were redirected through intermediary sites to a fake Slack-themed download page, where macOS users received a malicious DMG carrying the stealer, while Windows users were served a FakeBat payload, showing a cross-platform delivery operation. Researchers reported that the malware had been refreshed in late 2023 with added obfuscation designed to conceal strings, payload components, and command-and-control details from defenders.
Once launched on macOS, Atomic Stealer prompted victims for their system password and harvested browser data, saved credentials, cookies, cryptocurrency wallet information, and other sensitive files before exfiltrating the data to its operators. Separate analysis of the malware family has documented its focus on stealing high-value user data from Apple systems, while reporting around the campaign also tied the operation to a malware-as-a-service model promoted on Telegram, including discounted access offers that highlighted the commercialized nature of the threat.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On January 8, 2024, researchers identified a malvertising campaign using Google search ads impersonating Slack. The operation redirected victims through tracking infrastructure to a decoy Slack download site delivering FakeBat to Windows users and Atomic Stealer to macOS users.
The article states that malvertising activity distributing Atomic Stealer decreased during the holiday break and then resumed in early January 2024. This marked the return of active distribution after the seasonal slowdown.
The developers announced a Christmas Eve panel update that added a feature called Google Restore. The article links this feature to cookie-related abuse and session hijacking activity.
Earlier Atomic Stealer samples from December 12, 2023 contained identifying strings in clear text, including a command-and-control IP address. These artifacts were later removed in newer builds.
Atomic Stealer operators promoted a holiday discount on Telegram through December 31, 2023, reducing the malware's monthly subscription price from $3,000 to $2,000. The promotion highlighted the malware-as-a-service business model behind the stealer.
In mid-to-late December 2023, Atomic Stealer was updated to encrypt or hide strings and payload details to hinder detection. By around December 17, 2023, obfuscated samples were appearing and concealing command-and-control information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.