logo

AMOS infostealer targets macOS through a popular AI app

ID: 6896f33b-156b-5f4c-93bc-1bcb2d17f451

STIX ID: report--6896f33b-156b-5f4c-93bc-1bcb2d17f451

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-02-12

Date Updated: 2026-04-20

Author: Sponsored by Flare

...
...

This report analyzes the AMOS infostealer — a commercially sold macOS-focused stealer — covering its capabilities (keychain/browser session/crypto wallet/data exfiltration), distribution campaigns (phishing, fake installers, SEO poisoning, malvertising, poisoned AI extensions such as OpenClaw/ClawHub and ChatGPT shared-chat lures), and its role in a Malware-as-a-Service underground economy where stolen "stealer logs" are traded to enable account takeover, fraud, and cryptocurrency theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.