AMOS Infostealer Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
December 11, 2025
Last Seen
December 11, 2025

AMOS Infostealer is a macOS-targeting infostealer family observed in the ClickFix campaign, delivering its payload by piggybacking on the official ChatGPT website.

Overview

AMOS Infostealer is a macOS-targeting infostealer family observed in the ClickFix campaign, delivering its payload by piggybacking on the official ChatGPT website. This technique exemplifies abuse of trusted web infrastructure to host or deliver malware, expanding macOS threat activity and data‑theft capabilities. The development underscores the growing risk of credential and data theft on macOS through legitimate domain abuse.

Related Threat Clusters

  • New ClickFix Attacks Target macOS Users via ChatGPT Exploit

    A malicious campaign is targeting macOS users by exploiting the official ChatGPT website. Attackers are utilizing a ClickFix technique to distribute the AMOS infostealer through fake installation guides on chatgpt.com.…

    2 articles · Updated December 11, 2025

Recent Intelligence Reports

  • New ClickFix Attacks as macOS Infostealer Leverages Official ChatGPT Website by Piggybacking — Cybersecuritynews · December 11, 2025

Related Entities

CVSS v3.1 Breakdown