Executive Summary
Recent research has highlighted the emergence of AMOS stealer malware, which specifically targets macOS systems. This malware, first advertised on Telegram in April 2024, is designed to exfiltrate sensitive information, including login credentials and system data from various applications. An analysis conducted in a lab environment on August 5, 2026, provides insights into the infection process and the evolving nature of this threat.
Background
AMOS stealer is a significant player in the realm of macOS-targeted malware. It has been distributed through various channels, including ClickFix campaigns and malicious advertisements, often masquerading as cracked versions of popular software. The malware’s distribution methods highlight the ongoing risk to macOS users, particularly those seeking unauthorized software installations.
Characteristics of the Infection
The infection analyzed originated from a malicious website, getmacouscloud.com, which claimed to provide a macOS toolkit. The infection process involved executing a Z-shell script that retrieved a GZIP-compressed payload containing the AMOS stealer installer. This installer was saved in the /tmp directory and included additional files that facilitated the malware’s persistence on the infected system.
Infection Traffic
Post-infection analysis revealed that the malware communicated with a command and control (C2) server, sending HTTP POST requests that indicated the types of data being collected. The URLs associated with these requests suggest that AMOS stealer is actively designed to gather information from various applications, including web browsers and cryptocurrency wallets. The dynamic nature of the malware’s infrastructure, with frequent changes in domains and IP addresses, underscores its ongoing development and adaptation.
As AMOS stealer continues to evolve, it poses a growing threat to macOS users. Security professionals are advised to remain vigilant and monitor for indicators of compromise associated with this malware.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.



