AMOS Stealer Malware Targets macOS Users Through Malicious Toolkit Installations

Published:

Executive Summary

Recent research has highlighted the emergence of AMOS stealer malware, which specifically targets macOS systems. This malware, first advertised on Telegram in April 2024, is designed to exfiltrate sensitive information, including login credentials and system data from various applications. An analysis conducted in a lab environment on August 5, 2026, provides insights into the infection process and the evolving nature of this threat.

Background

AMOS stealer is a significant player in the realm of macOS-targeted malware. It has been distributed through various channels, including ClickFix campaigns and malicious advertisements, often masquerading as cracked versions of popular software. The malware’s distribution methods highlight the ongoing risk to macOS users, particularly those seeking unauthorized software installations.

Characteristics of the Infection

The infection analyzed originated from a malicious website, getmacouscloud.com, which claimed to provide a macOS toolkit. The infection process involved executing a Z-shell script that retrieved a GZIP-compressed payload containing the AMOS stealer installer. This installer was saved in the /tmp directory and included additional files that facilitated the malware’s persistence on the infected system.

Infection Traffic

Post-infection analysis revealed that the malware communicated with a command and control (C2) server, sending HTTP POST requests that indicated the types of data being collected. The URLs associated with these requests suggest that AMOS stealer is actively designed to gather information from various applications, including web browsers and cryptocurrency wallets. The dynamic nature of the malware’s infrastructure, with frequent changes in domains and IP addresses, underscores its ongoing development and adaptation.

As AMOS stealer continues to evolve, it poses a growing threat to macOS users. Security professionals are advised to remain vigilant and monitor for indicators of compromise associated with this malware.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Alleged Ploutus malware creator Anibal Canelon Aguirre appears in Nebraska court

The alleged mastermind behind the Ploutus malware, Anibal Alexander Canelon Aguirre, made his first court appearance in Nebraska after being apprehended by federal authorities....

AI-enabled threat actor JadePuffer automates destructive actions in cloud environments using Azure service principals

Recent research from Check Point has revealed that the AI-enabled threat actor known as JadePuffer, tracked as Storm-3168, is leveraging compromised Azure service principals...

FBI reports surge in AI-related online scams costing Alabamians over $6 million

The FBI has reported a significant rise in online scams fueled by artificial intelligence, marking the first time the bureau has tracked AI-related complaints...

US DHS allegedly compiles protester dossiers in Palantir database, court filing reveals

Newly unsealed court documents allege that the US Department of Homeland Security (DHS) has compiled extensive dossiers on individuals observing Immigration and Customs Enforcement...