Atomic macOS Stealer (AMOS) Targets Credentials via Malicious Terminal Commands

Atomic macOS Stealer (AMOS) Targets Credentials via Malicious Terminal Commands

First seen 4 Aug 2026, 16:28 UTC Isc.Sans.EduSocprime 81% similarity 70.5

Article Content

Browse articles
ThreatCluster

The Atomic macOS Stealer (AMOS) is a malware targeting macOS systems, distributed through malicious websites instructing users to paste commands into Terminal. The malware steals sensitive information such as browser credentials, messenger data, and cryptocurrency wallets. An investigation revealed that the infection was generated in a lab on July 31, 2026, and involved repeated command executions leading to persistent Mach-O binaries in various directories. Network analysis showed communication with a command and control (C2) server through HTTP POST and GET requests. Users are advised against executing untrusted commands and organizations should monitor for suspicious activities. Immediate isolation of infected devices is recommended to prevent data exfiltration, along with resetting passwords for affected accounts. The incident highlights the need for better user education regarding command execution in macOS.

Key Points: • AMOS malware targets macOS users by exploiting Terminal command execution. • Sensitive information, including browser credentials and cryptocurrency wallets, is at risk. • Organizations should implement monitoring for suspicious command-line activities.

ThreatCluster AI How this analysis works

Timeline

2026-07-31
AMOS infection generated in lab
A lab-generated infection of the AMOS stealer revealed its method of distribution via malicious Terminal commands.
Isc.Sans.Edu
2026-07-31
Initial infection traffic observed
Repeated command executions led to persistent Mach-O binaries on the infected macOS host.
Socprime
2026-08-02
Indicators of compromise published
Isc.Sans.Edu published IOCs related to the AMOS infection, including C2 traffic and SHA-256 hashes.
Isc.Sans.Edu
2026-08-04
Socprime article published
Socprime provided detailed analysis and recommendations for mitigating AMOS infections.
Socprime

Community

Browse all →

Tracked Entities in This Story