logo

When Stealers Converge: New Variant of Atomic Stealer in the Wild

ID: b691b222-f12b-5573-8fd1-fc6028ecd594

STIX ID: report--b691b222-f12b-5573-8fd1-fc6028ecd594

Feed Name: Bitdefender Labs

Threat Score
70/100

Date Published: 2024-02-27

Date Updated: 2026-04-27

Author: Andrei LAPUSNEANU

...
...

Bitdefender documents a new undetected macOS variant of the AMOS (Atomic) Stealer distributed via small DMG files containing FAT Mach-O dropper binaries; the droppers decode and drop an XOR-ed Python script that combines Python and AppleScript to harvest browser credentials, cookies, crypto wallet data, the login keychain and the local account password via a fake system update dialog, then packages the data in-memory and posts it to a hardcoded C2 (/p2p). The report supplies file hashes, C2 information, targeted browser-extension IDs, detections and notes code similarities with a recent RustDoor sample.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.