This article reviews an Atomic macOS (AMOS) stealer malware infection generated in a lab environment. While several sources have published articles analyzing AMOS stealer, the associated indicators constantly change. This article presents a snapshot of indicators seen in early August 2026 and is designed to help readers better understand AMOS stealer.
AMOS stealer is an information stealer targeting macOS systems that was advertised on Telegram as early as April 2024. AMOS stealer represents a noticeable portion of macOS stealer-based malware and is considered a growing threat. AMOS stealer exfiltrates system information, login credentials and other sensitive data from various applications, including web browsers and cryptocurrency wallets.
Malware that we’ve assessed as AMOS stealer has been distributed through ClickFix campaigns as well as through malicious ads. We’ve also seen AMOS stealer distributed through campaigns that claim to offer cracked versions of popular copyright-protected software. These sites offer instructions to install software such as a macOS toolkit but then actually install malware like AMOS stealer.
Read more…
Source: Palo Alto Unit 42
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
July 29, 2026
On July 22, 2026, Check Point published a security advisory for CVE-2026-16232, an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy ...
- Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems
July 29, 2026
Security researchers at Tenable suspect the Iran-linked faux hacktivist outfit CyberAv3ngers was behind the cyberattack that disrupted more than 30 Minnesota water facilities. Neither state-level nor federal officials have made any claims regarding attribution for the attacks, however, Tenable reckons the operational pattern is consistent with the crew’s previous raids, noting the timing relative to recent government warnings. The ...
- Mirage Kitten targets Middle East and Africa region with new malware
July 28, 2026
Mirage Kitten – also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore – is an advanced persistent threat (APT) group focused on cyber-espionage operations against aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa, using highly targeted spear-phishing campaigns, fake recruitment portals, and custom multi-stage malware to gain persistent access and exfiltrate sensitive data. During ...
- Hugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hack
July 26, 2026
After OpenAI recently admitted that one of its models had breached the systems of AI platform Hugging Face, Hugging Face’s CEO Clem Delangue posted on X that he was flying to San Francisco to have “a little chat with that ‘rogue agent.’” Then, in a follow-up post on Saturday, Delangue outlined what he’d asked for from OpenAI. He said he called ...
- What the First Autonomous Ransomware Case Confirms
July 24, 2026
Security researchers have documented an AI agent running a full ransomware operation on its own against a live production target, planning, adapting, and executing every step from the first exploit through data destruction. This is early real-world evidence of the shift to autonomous criminal operations that our research forecast. Agent-run attacks change what defenders can rely ...
- CISA has expanded the scope of its alert on Iranian-affiliated hackers attacking critical infrastructure
July 23, 2026
The US Cybersecurity and Infrastructure Security Agency (CISA) has expanded the scope of its alert on Iranian-affiliated hackers attacking critical infrastructure, including water and energy facilities. The original advisory focused on programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley. The update warns that the activity may also target devices from Schneider Electric, Siemens, “and potentially other branded/manufactured PLCs.” The conflict between ...

