Threat Actors Exploit AI Platforms to Distribute AMOS Stealer
Article Content
Browse articles
Threat actors are utilizing AI platforms like ChatGPT and Grok to distribute the Atomic macOS Stealer (AMOS). A campaign discovered by Huntress on December 5, 2025, indicates that attackers are leveraging user trust in these AI services to host malicious payloads.
Ask AI about this cluster
Answers cite the sources they use
Updated 212d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track AMOS Stealer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Kaspersky Uncovers New MacSync Malware Targeting macOS Users Kaspersky has identified an updated version of MacSync malware, which targets macOS users to steal credentials and cryptocurrency assets. This sophisticated infostealer, first detected in 2024-2025 as a variant of the AMOS stealer, employs a complex infection chain. The attack begins with users downloading a malicious…
Malicious Ad Delivers AMOS Stealer via Claude Code Impersonation On October 2, 2026, a malicious advertisement impersonating Claude Code was identified as the delivery method for the Atomic macOS (AMOS) Stealer malware. The ad led users to a site that mimicked legitimate software installation but instead installed the AMOS Stealer, which is designed to harvest sensitive information…