AMOS Stealer is a credential and data-stealer malware family that exfiltrates browser credentials, cookies, and tokens from infected hosts.
Overview
AMOS Stealer is a credential and data-stealer malware family that exfiltrates browser credentials, cookies, and tokens from infected hosts. A recent report states that threat actors are using AI-enabled tools such as ChatGPT and Grok Conversations to deliver AMOS Stealer, indicating an AI-assisted distribution vector. This combination of data-theft capabilities and novel delivery methods makes AMOS Stealer a notable and evolving threat in cybersecurity.
Related Threat Clusters
-
Atomic macOS Stealer (AMOS) Targets Credentials via Malicious Terminal Commands
The Atomic macOS Stealer (AMOS) is a malware targeting macOS systems, distributed through malicious websites instructing users to paste commands into Terminal. The malware steals sensitive information such as browser…
2 articles · Updated August 4, 2026 -
InstallFix Campaign Exploits AI Trust to Deliver Malware via Fake Install Pages
The InstallFix campaign targets users by creating fake installation pages for Anthropic's Claude AI, tricking them into executing malware. This sophisticated social engineering tactic exploits the growing reliance on AI…
53 articles · Updated May 5, 2026 -
MacSync Infostealer Exploits Google Search for Claude Installation
A malvertising campaign has emerged, using Google search results for Claude installation to deliver a macOS infostealer named MacSync. Victims are misled to a legitimate claude.ai shared conversation page, where they…
2 articles · Updated August 19, 2026 -
Fake Crypto Conference Lures Security Researchers into Malware Trap
A malicious campaign targeted cybersecurity professionals following the Black Hat and DEF CON conferences, using social engineering tactics. Attackers impersonated a CoinDesk executive and sent Google Docs that appeared…
13 articles · Updated August 20, 2026 -
Threat Actors Exploit AI Platforms to Distribute AMOS Stealer
Threat actors are utilizing AI platforms like ChatGPT and Grok to distribute the Atomic macOS Stealer (AMOS). A campaign discovered by Huntress on December 5, 2025, indicates that attackers are leveraging user trust in…
2 articles · Updated December 10, 2025 -
Cybercriminals Use AI Chatbots and Google Ads to Distribute macOS AMOS Stealer
Cybercriminals have launched an attack campaign utilizing ChatGPT and Grok alongside Google Ads to distribute the Atomic macOS Stealer (AMOS). This campaign targets Mac users by exploiting their trust in AI platforms,…
3 articles · Updated February 11, 2026
Recent Intelligence Reports
- Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware — Huntress · August 19, 2026
- MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer — Huntress · August 17, 2026
- Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd) — Isc.Sans.Edu · August 2, 2026
- Google Ads and Claude.ai Shared Chats Abused to Distribute Mac Malware — Technadu · May 11, 2026
- Hackers Exploit ChatGPT, Grok and Google Ads to Spread macOS AMOS Stealer — Gbhackers · February 11, 2026
- Threat Actors Exploit ChatGPT and Grok Conversations to Deliver AMOS Stealer — Gbhackers · December 10, 2025