Atomic macOS Stealer (AMOS) Targets Credentials via Malicious Terminal Commands
ID: 01f8257f-6bf0-53bd-a295-77c24f55ef27
STIX ID: report--01f8257f-6bf0-53bd-a295-77c24f55ef27
Feed Name: ThreatCluster
Threat Score
**Executive Summary:** The Atomic macOS Stealer (AMOS) is a macOS infostealer distributed via malicious websites that trick users into pasting commands into Terminal; it installs persistent Mach-O binaries, exfiltrates browser credentials, messenger data, and cryptocurrency wallets to an HTTP-based C2, and organizations are advised to monitor for suspicious command-line activity, isolate infected devices, and reset affected credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
