logo

The journey into Mac OS infostealers

ID: f12f2755-4c05-5242-9ecf-5e1d34d400f0

STIX ID: report--f12f2755-4c05-5242-9ecf-5e1d34d400f0

Feed Name: infostealers.com

Threat Score
70/100

Date Published: 2024-09-18

Date Updated: 2026-04-28

Author: Alon Gal

...
...

This investigative timeline summarizes the evolution of Mac OS infostealers from the early 0xFFF/OSx Stealer through the AMOS fork and subsequent Poseidon/Cthulhu/Banshee variants, documenting developer interactions, marketplace sales and exit scams, and operational details (DMG installers, Gatekeeper/workarounds, Telegram/AnonFiles exfiltration). The report highlights active criminal use targeting browser credentials and cryptocurrency wallets, developer disputes and source-code trades, and the consolidation of AMOS as the primary Mac infostealer in the market.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.