AMOS Stealer Malware Targets macOS Users Through Malicious Toolkit Installations

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Executive Summary

Recent research has highlighted the emergence of AMOS stealer malware, which specifically targets macOS systems. This malware, first advertised on Telegram in April 2024, is designed to exfiltrate sensitive information, including login credentials and system data from various applications. An analysis conducted in a lab environment on August 5, 2026, provides insights into the infection process and the evolving nature of this threat.

Background

AMOS stealer is a significant player in the realm of macOS-targeted malware. It has been distributed through various channels, including ClickFix campaigns and malicious advertisements, often masquerading as cracked versions of popular software. The malware’s distribution methods highlight the ongoing risk to macOS users, particularly those seeking unauthorized software installations.

Characteristics of the Infection

The infection analyzed originated from a malicious website, getmacouscloud.com, which claimed to provide a macOS toolkit. The infection process involved executing a Z-shell script that retrieved a GZIP-compressed payload containing the AMOS stealer installer. This installer was saved in the /tmp directory and included additional files that facilitated the malware’s persistence on the infected system.

Infection Traffic

Post-infection analysis revealed that the malware communicated with a command and control (C2) server, sending HTTP POST requests that indicated the types of data being collected. The URLs associated with these requests suggest that AMOS stealer is actively designed to gather information from various applications, including web browsers and cryptocurrency wallets. The dynamic nature of the malware’s infrastructure, with frequent changes in domains and IP addresses, underscores its ongoing development and adaptation.

As AMOS stealer continues to evolve, it poses a growing threat to macOS users. Security professionals are advised to remain vigilant and monitor for indicators of compromise associated with this malware.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Infoblox Research Reveals 1.7 Million Chinese Casino Domains Linked to Cybercrime and Fraud

Infoblox Threat Intel has uncovered a staggering 1.7 million Chinese-language casino domains that are linked to various forms of cybercrime, including illegal gambling and...

CrowdStrike Enhances Data Security with On-Device AI for Real-Time Classification

As organizations increasingly rely on digital platforms, the need for robust data security has never been more critical. Modern data security hinges on the...

NASA restores Guam Remote Station after Super Typhoon Mawar damage

NASA has successfully restored its Guam Remote Station, marking the completion of a recovery effort that lasted over three years following the devastation caused...

International Meteor Organization Faces Extended Downtime Following Cyberattack

The International Meteor Organization (IMO), a nonprofit dedicated to coordinating and publishing observations of meteor phenomena, has reported significant disruptions to its infrastructure due...