Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)
ID: 786a0c83-d73d-5815-a198-8de32b13ae8a
STIX ID: report--786a0c83-d73d-5815-a198-8de32b13ae8a
Feed Name: SANS ISC Diary
This lab report documents an AMOS macOS infostealer infection observed on 2026-07-31: a malicious webpage coerced a user to paste a command into Terminal to download and install the stealer. The report includes the initial distribution URLs, payload download links, C2 endpoints (notably 188.166.78.138), multiple SHA-256 hashes, sample file locations and sizes, persistence paths on the infected macOS host, and network traffic captures — all provided to support detection and incident response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
