logo

Why AMOS matters: The macOS malware stealing data at scale

ID: 37eac375-0763-5c8c-a9e2-72c5e3bd6263

STIX ID: report--37eac375-0763-5c8c-a9e2-72c5e3bd6263

Feed Name: Sophos Blogs

Threat Score
75/100

Date Published: 2026-05-11

Date Updated: 2026-05-27

...
...

Sophos MDR reports on an active AMOS (Atomic macOS) infostealer campaign that leverages ClickFix-style social engineering to execute a bootstrap script, capture the victim's macOS password, deploy an elevated second-stage stealer, perform anti-analysis checks, harvest Keychain, browser and cryptocurrency credentials, archive and exfiltrate data to attacker-controlled C2 servers, and maintain persistence via LaunchDaemons; the report includes technical artifacts, example IOCs, MITRE ATT&CK mapping, and detection/prevention recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.