AMOS Stealer Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
December 10, 2025
Last Seen
August 19, 2026

AMOS Stealer is a credential and data-stealer malware family that exfiltrates browser credentials, cookies, and tokens from infected hosts.

Overview

AMOS Stealer is a credential and data-stealer malware family that exfiltrates browser credentials, cookies, and tokens from infected hosts. A recent report states that threat actors are using AI-enabled tools such as ChatGPT and Grok Conversations to deliver AMOS Stealer, indicating an AI-assisted distribution vector. This combination of data-theft capabilities and novel delivery methods makes AMOS Stealer a notable and evolving threat in cybersecurity.

Related Threat Clusters

Recent Intelligence Reports

  • Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware — Huntress · August 19, 2026
  • MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer — Huntress · August 17, 2026
  • Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd) — Isc.Sans.Edu · August 2, 2026
  • Google Ads and Claude.ai Shared Chats Abused to Distribute Mac Malware — Technadu · May 11, 2026
  • Hackers Exploit ChatGPT, Grok and Google Ads to Spread macOS AMOS Stealer — Gbhackers · February 11, 2026
  • Threat Actors Exploit ChatGPT and Grok Conversations to Deliver AMOS Stealer — Gbhackers · December 10, 2025

CVSS v3.1 Breakdown