Socprime Atomic macOS Stealer (AMOS) Targets Credentials via Malicious Terminal Commands
Article Content
- •AMOS malware targets macOS users by exploiting Terminal command execution.
- •Sensitive information, including browser credentials and cryptocurrency wallets, is at risk.
- •Organizations should implement monitoring for suspicious command-line activities.
The Atomic macOS Stealer (AMOS) is a malware targeting macOS systems, distributed through malicious websites instructing users to paste commands into Terminal. The malware steals sensitive information such as browser credentials, messenger data, and cryptocurrency wallets. An investigation revealed that the infection was generated in a lab on July 31, 2026, and involved repeated command executions leading to persistent Mach-O binaries in various directories. Network analysis showed communication with a command and control (C2) server through HTTP POST and GET requests. Users are advised against executing untrusted commands and organizations should monitor for suspicious activities. Immediate isolation of infected devices is recommended to prevent data exfiltration, along with resetting passwords for affected accounts. The incident highlights the need for better user education regarding command execution in macOS.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track AMOS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Infostealer Malware Hijacks Claude Sessions, Drains User Accounts Anthropic has alerted users that infostealer malware is compromising Claude accounts by hijacking active login sessions, allowing attackers to deplete usage limits without needing passwords or two-factor authentication. The malware, identified as Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic…
HBO Max Account Compromise Fuels ClickFix Malware Campaign In September 2026, hackers compromised the verified HBO Max Reddit account, launching a ClickFix campaign that distributed 108 malicious ads over 48 hours. The ads targeted both macOS and Windows users, tricking them into executing commands that installed information-stealing malware. This operation, dubbed…