Malware-Traffic-Analysis Malicious Ad Delivers AMOS Stealer via Claude Code Impersonation
Article Content
- •AMOS Stealer malware delivered via a malicious ad impersonating Claude Code.
- •Users were tricked into installing malware disguised as legitimate software.
- •The incident underscores the risks of social engineering in cybersecurity.
On October 2, 2026, a malicious advertisement impersonating Claude Code was identified as the delivery method for the Atomic macOS (AMOS) Stealer malware. The ad led users to a site that mimicked legitimate software installation but instead installed the AMOS Stealer, which is designed to harvest sensitive information from macOS systems. The malware was distributed through password-protected zip files, and users were prompted for permissions during installation. This incident highlights the ongoing threat of social engineering tactics in malware distribution. The scope of the impact is currently unclear, as the number of affected users has not been disclosed. The malware's detection and mitigation measures are still being assessed. No specific CVEs have been reported in relation to this incident.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track AMOS Stealer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
How does the AMOS Stealer infect systems?
What systems are affected by this malware?
What should users do if they suspect infection?
Continue Reading
Kaspersky Uncovers New MacSync Malware Targeting macOS Users Kaspersky has identified an updated version of MacSync malware, which targets macOS users to steal credentials and cryptocurrency assets. This sophisticated infostealer, first detected in 2024-2025 as a variant of the AMOS stealer, employs a complex infection chain. The attack begins with users downloading a malicious…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…