logo

Why AMOS matters: The macOS malware stealing data at scale

ID: ad09e989-5818-56b1-bcd8-9953f0fd08b9

STIX ID: report--ad09e989-5818-56b1-bcd8-9953f0fd08b9

Feed Name: Sophos Blogs

Threat Score
75/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

...
...

Sophos MDR investigated an active AMOS (Atomic macOS) infostealer campaign that leverages ClickFix-style social engineering to run a bootstrap script, capture and validate macOS passwords, deploy a second-stage payload with elevated privileges, perform anti-analysis checks, harvest Keychain and browser credentials (including crypto wallet-related artifacts), archive data, exfiltrate to attacker C2 infrastructure, and maintain persistence via LaunchDaemons; the report includes example IOCs, MITRE ATT&CK mapping, detection opportunities, and prevention recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.