logo

Atomic Stealer Gets an Upgrade - Targeting Mac Users with Encrypted Payload

ID: 64048ab0-7c7d-52e1-a23c-518e1d991dac

STIX ID: report--64048ab0-7c7d-52e1-a23c-518e1d991dac

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-01-11

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

Researchers have identified an updated macOS information stealer called Atomic (AMOS) that introduced payload encryption and obfuscation to bypass detection. The malware, sold as a commercial service (now up to $3,000/month), steals Keychain passwords, session cookies, files, crypto wallets, system metadata and the machine password via fake prompts, and is being distributed via malvertising, compromised sites, and fraudulent Slack disk images or loaders like EugenLoader.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.