AMOS Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
24
occurrences
First Seen
December 5, 2025
Last Seen
June 10, 2026

AMOS is a malware family tracked across 15 threat clusters and 24 intelligence report mentions on ThreatCluster. First observed December 5, 2025; most recent activity June 10, 2026.

Related Threat Clusters

  • Bybit Exposes Multi-Stage Malware Targeting Claude Code Users

    Bybit's Security Operations Center (SOC) reported a sophisticated malware campaign targeting macOS users searching for 'Claude Code,' an AI development tool from Anthropic. The campaign, first identified in March 2026,…

    5 articles · Updated April 21, 2026
  • Weaponized DMG Files Target macOS Users with Infostealer Malware

    Hackers are exploiting macOS users through weaponized DMG files that masquerade as legitimate software installers. This tactic leverages the misconception that Apple devices are immune to malware, allowing attackers to…

    3 articles · Updated June 11, 2026
  • New MacSync Malware Exploits Apple Notarization to Steal User Credentials

    A new variant of the MacSync stealer malware has been identified, exploiting Apple's notarization process to bypass security measures on macOS devices. This malware poses a risk to sensitive user data by disguising…

    16 articles · Updated December 22, 2025
  • Malware Campaign Targets TradingView Users via Fake Reddit Posts

    A new malware campaign is exploiting fake posts on Reddit that promise free access to TradingView Premium, targeting both Windows and macOS users. The malware distributed includes Vidar, which steals information from…

    2 articles · Updated April 7, 2026
  • Infostealer Campaigns Expand to Target macOS Systems

    Infostealer threats have shifted from primarily targeting Windows to macOS environments, as reported by the Microsoft Defender Security Research Team. Since late 2025, these campaigns have utilized cross-platform…

    13 articles · Updated February 4, 2026
  • Malvertising Campaign Distributes AMOS ‘malext’ Infostealer to macOS Users

    A malvertising campaign has emerged, targeting macOS users globally with a new variant of the AMOS infostealer known as 'malext.' Attackers are utilizing Google ads to direct victims to fake help articles on…

    3 articles · Updated March 3, 2026
  • State-Sponsored Hackers Exploit Google's Gemini AI for Cyberattacks

    State-backed hackers from China, Iran, North Korea, and Russia are utilizing Google's Gemini AI model to facilitate various stages of cyberattacks, including reconnaissance and post-compromise actions. Notably, the…

    162 articles · Updated February 12, 2026
  • New AMOS Malware Targets macOS Users via Deceptive Tactics

    A new malware called Atomic macOS Stealer (AMOS) is targeting macOS users through deceptive methods. Attackers are using fake Google ads, lookalike websites, and fraudulent links to trick users into executing harmful…

    1 article · Updated December 19, 2025
  • Malware Spread via ChatGPT Ads Targets macOS Users

    Threat actors are using paid ads on Google to promote misleading conversations with ChatGPT and Grok, which appear to offer tech support but actually lead macOS users to download infostealing malware. This campaign is a…

    2 articles · Updated December 15, 2025
  • Hackers Use AI Tools to Spread Malware via Google Search Results

    Hackers are exploiting AI tools like ChatGPT and Grok to create malicious commands that appear in Google search results. When users unknowingly execute these commands, they inadvertently allow hackers to install malware…

    3 articles · Updated December 11, 2025

Recent Intelligence Reports

  • Deceptive Installers: How Fake Apps Target macOS — Huntress · June 10, 2026
  • Bybit Security exposes macOS malware campaign targeting users searching for Claude Code — Mexc.Co · April 21, 2026
  • Bybit Security exposes macOS malware campaign targeting users searching for Claude Code — Cryptonews · April 21, 2026
  • Bybit Uncovers AI — Prnewswire · April 21, 2026
  • Bybit Uncovers AI — Prnewswire · April 21, 2026
  • Fake TradingView Premium Reddit Posts Spread Vidar and AMOS Stealers — Gbhackers · April 7, 2026
  • Malvertising Delivers AMOS 'malext' Infostealer via Fake Text-Sharing Ads — Cyberpress · March 4, 2026
  • Malvertising Campaign Delivers AMOS ‘malext’ macOS Infostealer via Fake Text‑Sharing Lures — Cybersecuritynews · March 3, 2026

CVSS v3.1 Breakdown