logo

Atomic macOS Stealer (AMOS) Targets Credentials via Malicious Terminal Commands

ID: 01f8257f-6bf0-53bd-a295-77c24f55ef27

STIX ID: report--01f8257f-6bf0-53bd-a295-77c24f55ef27

Feed Name: ThreatCluster

Threat Score
65/100

Date Published: 2026-08-04

Date Updated: 2026-08-05

...
...

**Executive Summary:** The Atomic macOS Stealer (AMOS) is a macOS infostealer distributed via malicious websites that trick users into pasting commands into Terminal; it installs persistent Mach-O binaries, exfiltrates browser credentials, messenger data, and cryptocurrency wallets to an HTTP-based C2, and organizations are advised to monitor for suspicious command-line activity, isolate infected devices, and reset affected credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.