logo

Malvertising Campaign Spreads AMOS ‘malext’ macOS Infostealer via Fake Text-Sharing Ads

ID: 2351e254-70d6-5f43-bc18-df49c1ec4fa2

STIX ID: report--2351e254-70d6-5f43-bc18-df49c1ec4fa2

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-03-03

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A global malvertising campaign uses fake Google Ads and Medium-style lures to trick macOS users into running obfuscated shell commands that install an AMOS infostealer variant (“malext”). The malware supports both ARM and x86_64, performs VM/sandbox checks, strips quarantine attributes to evade Gatekeeper, steals browsers, wallets, Apple Notes, keychain and files, establishes persistence via LaunchDaemons and trojanized apps, and exfiltrates data to malext.com and fallback IPs; researchers observed dozens of compromised ad accounts and multiple IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.