logo

AI-Poisoning & AMOS Stealer: How Trust Became the Biggest Mac Threat

ID: d458d842-3a70-5071-bf50-e0a662f4e5ac

STIX ID: report--d458d842-3a70-5071-bf50-e0a662f4e5ac

Feed Name: Huntress Blog

Threat Score
80/100

Date Published: 2025-12-09

Date Updated: 2026-04-28

...
...

Huntress details an active AMOS macOS infostealer campaign that poisons search results and maliciously authored ChatGPT/Grok conversations to trick users into copying Terminal commands; these commands fetch a loader that harvests credentials (via dscl-authonly), escalates to root, deploys a persistent Mach-O stealer (.helper), trojanizes wallet apps, and exfiltrates sensitive data. The report includes a high-level technical analysis, persistence and watchdog techniques, IOCs (file hashes, filenames, IPs, domains), and detection/mitigation recommendations for defenders and end users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.