Why AMOS matters: The macOS malware stealing data at scale
ID: ad09e989-5818-56b1-bcd8-9953f0fd08b9
STIX ID: report--ad09e989-5818-56b1-bcd8-9953f0fd08b9
Feed Name: Sophos Blogs
Sophos MDR investigated an active AMOS (Atomic macOS) infostealer campaign that leverages ClickFix-style social engineering to run a bootstrap script, capture and validate macOS passwords, deploy a second-stage payload with elevated privileges, perform anti-analysis checks, harvest Keychain and browser credentials (including crypto wallet-related artifacts), archive data, exfiltrate to attacker C2 infrastructure, and maintain persistence via LaunchDaemons; the report includes example IOCs, MITRE ATT&CK mapping, detection opportunities, and prevention recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
