logo

Atomic macOS Stealer now includes a backdoor for persistent access

ID: 2005a49e-6360-5dc5-8347-c14e3a252566

STIX ID: report--2005a49e-6360-5dc5-8347-c14e3a252566

Feed Name: infostealers.com

Threat Score
80/100

Date Published: 2025-07-08

Date Updated: 2026-04-28

Author: Alon Gal

...
...

Moonlock Lab reports that the Atomic macOS Stealer (AMOS), a widely distributed macOS stealer active in over 120 countries, has been updated to include an embedded backdoor that enables persistent, remote, user-level access and execution of C2-assigned tasks. The report details delivery via trojanized DMGs and spear-phishing, the installation and persistence mechanisms (LaunchDaemon, .agent/.helper), C2 APIs and commands, observable IOCs (multiple 45.94.47.* IPs, URLs, and SHA256s), and warns that this evolution significantly increases the risk to macOS users by converting one-time data theft into long-term compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.