Skip to content
Malicious Ad Delivers AMOS Stealer via Claude Code Impersonation

Malicious Ad Delivers AMOS Stealer via Claude Code Impersonation

First seen 5 Oct 2026, 05:06 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 06:03 UTC
  • •AMOS Stealer malware delivered via a malicious ad impersonating Claude Code.
  • •Users were tricked into installing malware disguised as legitimate software.
  • •The incident underscores the risks of social engineering in cybersecurity.

On October 2, 2026, a malicious advertisement impersonating Claude Code was identified as the delivery method for the Atomic macOS (AMOS) Stealer malware. The ad led users to a site that mimicked legitimate software installation but instead installed the AMOS Stealer, which is designed to harvest sensitive information from macOS systems. The malware was distributed through password-protected zip files, and users were prompted for permissions during installation. This incident highlights the ongoing threat of social engineering tactics in malware distribution. The scope of the impact is currently unclear, as the number of affected users has not been disclosed. The malware's detection and mitigation measures are still being assessed. No specific CVEs have been reported in relation to this incident.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-02
AMOS Stealer infection reported
A malicious ad impersonating Claude Code was identified as the source of AMOS Stealer infections on macOS systems.
Malware-Traffic-Analysis
2026-10-03
Previous ClickFix activity noted
Prior to the AMOS Stealer incident, ClickFix activity was observed, but the specific malware involved was not identified.
Malware-Traffic-Analysis

More articles in this cluster (2)

Following this threat?

Track AMOS Stealer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

How does the AMOS Stealer infect systems?
The AMOS Stealer is delivered through a malicious ad that impersonates legitimate software, prompting users to install it.
What systems are affected by this malware?
The AMOS Stealer targets macOS systems, but the exact number of affected users is currently unknown.
What should users do if they suspect infection?
Users should run a security scan on their macOS systems and remove any unauthorized applications or files.