TF-MAL-osx.amos
📛 Threat Title
Malware family: AMOS
Description
ThreatFox malware family `osx.amos`. Printable name: AMOS. Aliases: Atomic macOS Stealer.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.amos
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.amos
IOC database
- Type
- domain
- Value
osx.amos- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.amos
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.amos
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.netmanageit.com
The AMOS stealer campaign exemplifies how threat actors adapt to macOS security enhancements and exploit social engineering to achieve data exfiltration. As the threat landscape evolves, organizations and individuals must remain vigilant, adopt robust detection mechanisms, and foster a security-aware culture to counter emerging threats.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the AMOS malware family including references, samples and yara signatures.
-
web:undercodetesting.com
Key Takeaway 1: AMOS's backdoor functionality marks a shift toward macOS-targeted advanced persistent threats (APTs), requiring proactive monitoring. Key Takeaway 2: Defense-in-depth—combining endpoint detection, network filtering, and user education—is critical to mitigate such threats.
-
web:www.bleepingcomputer.com
Malware analyst discovered a new version of the Atomic macOS info-stealer (also known as 'AMOS' ) that comes with a backdoor, to give attackers persistent access to compromised systems.
-
web:www.broadcom.com
Trend Micro's latest report reveals a sophisticated campaign leveraging the AMOS infostealer (also known as Atomic macOS Stealer). Attackers employ social engineering, disguising the malware binaries as cracked software or tricking users into pasting malicious commands into the macOS Terminal thus bypassing built-in protections like Gatekeeper. The campaign utilizes rotating domains to evade ...
-
web:www.cloudsek.com
CloudSEK researchers have uncovered a sophisticated campaign leveraging typo-squatted "Spectrum" domains to spread a new Atomic macOS Stealer ( AMOS ) variant. Disguised as a CAPTCHA verification, the attack uses dynamic payloads tailored to the victim's OS—stealing passwords, bypassing macOS security, and executing malware . With Russian-language comments found in the code and flawed ...
-
web:www.huntress.com
Attackers are exploiting user trust in AI and aggressive SEO to deliver an evolved Atomic macOS Stealer. Learn why this social engineering tradecraft bypasses traditional network controls and the future of macOS infostealer defense.
-
web:www.intego.com
Atomic Stealer ( AMOS ) has had brand-new, active Mac malware campaigns over the past two weeks. Intego has exclusive coverage of the latest threats, how to avoid them, and how to clean an infection from your Mac.
-
web:www.microsoft.com
These commands, which are purported to install system utilities, load an infostealing malware like Macsync, Shub Stealer, and AMOS into the targets' devices instead. The malware then collects and exfiltrates data, including media files, iCloud data and Keychain entries, and cryptocurrency wallet keys.
-
web:www.trendmicro.com
Trend™ Research analyzed a campaign distributing Atomic macOS Stealer ( AMOS ), a malware family targeting macOS users. Attackers disguise the malware as "cracked" versions of legitimate apps, luring users into installation.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.