Security News

Cybersecurity news aggregator

HIGH Attacks Unit 42

Atomic macOS (AMOS) Stealer Activity

The Atomic macOS (AMOS) stealer is a growing threat distributed via malicious sites posing as cracked software or toolkits, which instruct victims to paste malicious commands into a macOS Terminal. The stealer exfiltrates system information, credentials, and cryptocurrency wallet data. The article provides a snapshot of indicators from August 2026 to aid detection, as these indicators are constantly changing.
Read Full Article →

Threat Research Center Insights General General Atomic macOS (AMOS) Stealer Activity 7 min read Related Products Advanced DNS Security Advanced URL Filtering By: Bradley Duncan Published: September 16, 2026 Categories: General Insights Malware Tags: MacOS Malware Threat intelligence Share Executive Summary This article reviews an Atomic macOS (AMOS) stealer malware infection generated in a lab environment. While several sources have published articles analyzing AMOS stealer, the associated indicators constantly change. This article presents a snapshot of indicators seen in early August 2026 and is designed to help readers better understand AMOS stealer. Background AMOS stealer is an information stealer targeting macOS systems that was advertised on Telegram as early as April 2024 . AMOS stealer represents a noticeable portion of macOS stealer-based malware and is considered a growing threat . AMOS stealer exfiltrates system information, login credentials and other sensitive data from various applications, including web browsers and cryptocurrency wallets . Malware that we've assessed as AMOS stealer has been distributed through ClickFix campaigns as well as through malicious ads . We've also seen AMOS stealer distributed through campaigns that claim to offer cracked versions of popular copyright-protected software. These sites offer instructions to install software such as a macOS toolkit but then actually install malware like AMOS stealer. This article examines an AMOS stealer infection generated on Aug. 5, 2026, from an instructional page claiming to install a “macOS toolkit.” Characteristics of the Infection The domain hosting the malicious page claiming to have installation instructions for a macOS toolkit is getmacouscloud[.]com . An example of one of the pages is shown below in Figure 1. Figure 1. A malicious website advertising a quick setup for “macOS toolkit.” While the “quick setup” instructions from this page in Figure 1 are sometimes described as a ClickFix technique, this is not really ClickFix. The ClickFix technique generally uses a fake CAPTCHA or other type of verification page offering instructions to continue to the website a viewer intends to visit. ClickFix campaigns inject a script into a viewer's clipboard to paste into a Run window for Windows systems or a Terminal window for macOS systems. Regardless of what we call this copy/paste technique, we followed the instructions in our lab environment. We copied text from the page and pasted it into a Terminal window on our macOS system as shown in Figure 2. Figure 2. Malicious text pasted into a Terminal window. The command in Figure 2 retrieved a Z-shell (Zsh) script from hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688 . That Zsh script contains Base64-encoded text for a GZIP-compressed payload as shown in Figure 3. Figure 3. Base64-encoded GZIP-compressed payload in the initial Zsh script. That GZIP-compressed payload contains a follow-up Zsh script designed to retrieve and run a Mach-O binary to install AMOS stealer. That Mach-O binary for the AMOS stealer installer was saved as /tmp/helper , as shown below in Figure 4. The same directory also contained a plist file named starter , also shown in Figure 4. Figure 4. Mach-O binary for AMOS stealer installer and plist file. The plist file at /tmp/starter contains text that hints at a newly created file in the user's /Library/Application Support/.com.apple.accountsd/ directory named .service . This file is a shell script that runs a Mach-O file for AMOS stealer in the same directory named AccountsHelper , as shown in Figure 5. Figure 5. Files in the /Library/Application Support/.com.apple.accountsd/ directory. We found an additional directory and similar files in the user's /Library/Application Support/.com.apple.metadata.mds/ directory named . mdworker and mdworker_shared ., as shown below in Figure 6. The . mdworker file is a shell script that runs another AMOS stealer Mach-O file named mdworker_shared . Figure 6. Files in the /Library/Application Support/.com.apple.metadata.mds/ directory. Of note, before the infection would proceed, the macOS host presented a prompt to enter the user's password as shown below in Figure 7. Since the user account on this macOS host was an administrative account, it proceeded when we entered the user's password. Figure 7. Prompt for the user's password. After entering the user's password, the host's Terminal process presented prompts requesting various permissions during the infection, as noted below in Figure 8. Figure 8. Prompts by the Terminal process during the infection. After running the initial malicious text in the Terminal window, the Terminal process requested the following permissions: Access to control the macOS Finder application Access to files in the user's Desktop folder Access to files in the user's Documents folder Access to control the macOS Notes application AMOS stealer collected and temporarily saved information under the host's /tmp directory, and compressed the data into a file named out.zip . The file and directory structure of the out.zip file follows: Directory: deskwallets/Binance/ Directory: deskwallets/TonKeeper/ Directory: FileGrabber/aws/ Directory: FileGrabber/docker/ Directory: FileGrabber/filezilla/ Directory: FileGrabber/gcloud/ File: FileGrabber/zsh_history File: info Directory: Telegram Data/ File: username The infected macOS host was a clean installation with no additional added applications. However, the file and directory content of out.zip hints at the applications that AMOS stealer searched for during this infection. Infection Traffic Post-infection traffic consisted mainly of HTTP POST requests to a command and control (C2) server at 161.35.146[.]120 . Figure 9 shows traffic from the infection filtered in Wireshark. Figure 9. Traffic from the infection filtered in Wireshark. As shown above in Figure 9, URLs for the initial HTTP POST requests hint at the types of data collected by AMOS stealer. These initial URLs end with the following strings: stage=boot stage=init_session stage=messengers stage=credentials stage=browsers stage=wallets stage=resolve_auth stage=local_data Comparing this AMOS stealer infection on Aug. 5, 2026, with a previous infection on July 31, 2026 , reveals similar post-infection URL patterns. However, that AMOS stealer infection generated traffic to a different C2 server at 188.166.78[.]138 . This comparison underscores a notable characteristic of AMOS stealer and its supporting infrastructure. The associated domains, URLs and IP addresses frequently change for AMOS stealer activity. The same frequent changes apply to filenames, file hashes and directory paths seen in our post-infection forensic analysis. These different AMOS stealer characteristics over a relatively brief period indicate this is a malware family in active development, which is continually evolving. Conclusion This article reviewed an Atomic stealer malware infection from early August 2026. The resulting analysis includes behavior from the infected macOS host, malware samples, post-infection artifacts and traffic patterns that indicate the types of information collected by this malware. The key to understanding AMOS stealer is realizing this malware is continually evolving. The indicators frequently change, and the ones we present in this research are no longer the most current. However, the overall patterns of activity remain consistent. While this review is a snapshot, analysts and other security professionals can better understand AMOS stealer by keeping track of its changes in the coming weeks and months. Palo Alto Networks customers are better protected from AMOS stealer and related threats through the following products and services: Advanced URL Filtering and Advanced DNS Security identify known domains and URLs associated with this activity as malicious. If you think you may have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call: North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42) UK: +44.20.3743.3660 Europe and Middle East: +31.20.299.3130 Asia: +65.6983.8730 Japan: +81.50.1790.0200 Australia: +61.2.4062.7950 India: 000 800 050 45107 South Korea: +82.080.467.8774 Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the Cyber Threat Alliance . Indicators of Compromise We discovered the following five files during this AMOS stealer infection: Initial Zsh script downloaded from a command run from the macOS Terminal window SHA-256 hash: 71781ad8adefb499aee9bcbe1a166e69ccc37a47066682f617d65c76d8cde88c File size: 1,991 bytes File type: Zsh script text executable, ASCII text File location: hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688 Payload (Zsh script) extracted from the initially downloaded Zsh script SHA-256 hash: 7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ffd3d1c154d40d7ca3a File size: 1,213 bytes File type: Zsh script text executable, ASCII text, ASCII text, with very long lines (323) Installer for AMOS stealer SHA-256 hash: a598fcdcd49247312861ff90c16cb4a5d49fede6072e30e7416dd276668fa2a9 File size: 330,768 bytes File location: /tmp/helper File type: Mach-O universal binary with two architectures: x86_64 and ARM64 Binary from AMOS stealer infection persistent on the infected macOS host SHA-256 hash: 6bfcdb4920383375b7e519918df7eb4db751b974b5571a15ce66b82478012620 File size: 438,576 bytes File location: /Users/[username]/Library/Application Support/.com.apple.accountsd/AccountsHelper File type: Mach-O universal binary with two architectures: x86_64 and ARM64 Another binary from AMOS stealer infection persistent on the infected macOS host SHA-256 hash: 4504006d19110

Share this article