Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activitysearch-ad-manipulationcybercrime-service-ecosystemdefense-evasion-method

AMOS Mac Malware Spreads via Fake Ads and Trojanized macOS Downloads

Updated 28d agoFirst seen May 25, 20266 sources

Researchers reported multiple campaigns distributing macOS infostealers tied to the AMOS/AtomicStealer ecosystem, a malware-as-a-service operation that steals credentials, browser data, cryptocurrency wallets, Apple Notes, files, and Keychain material from macOS Catalina and newer systems on Intel, M1, and M2 devices. Earlier reporting on related macOS stealers showed operators relying on social engineering, unsigned DMG files, and password prompts to collect sensitive data, package it into archives, and exfiltrate it to command-and-control servers, with some activity also summarized to Telegram channels.

More recent campaigns used malvertising and fake software or troubleshooting pages to lure users into running Terminal commands that fetched an AMOS variant known as "malext". Investigators said the malware used obfuscated shell commands, osascript, quarantine removal, anti-VM and sandbox checks, and in some cases installed persistence through a LaunchDaemon and helper scripts, while also trojanizing Ledger and Trezor applications and capturing administrator passwords. Reporting also linked AMOS delivery to fake CleanMyMac sites and AI-themed lures, indicating operators are rapidly rotating ad accounts and adapting infection vectors to broaden theft and remote access on macOS systems.

Share:
AMOS Mac Malware Spreads via Fake Ads and Trojanized macOS Downloads
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Mar 6, 20264mo ago

Fake CleanMyMac campaign reported delivering macOS malware

Cybernews reported a fake CleanMyMac-themed campaign targeting Mac users and delivering malware with cryptocurrency theft impacts. The report represents another publicly disclosed AMOS-related social-engineering distribution campaign affecting macOS users.

Mar 3, 20264mo ago

Researchers uncover AMOS 'malext' malvertising campaign

Researchers uncovered a large-scale malvertising campaign using fake Google Ads and malicious text-hosting pages to trick macOS users into running Terminal commands that installed an AMOS variant dubbed 'malext.' Google Ads Library data cited in the report showed more than 34 ads and at least 53 compromised ad accounts involved.

Feb 2, 20265mo ago

AMOS activity linked to operations active since late 2025

Researchers assessing later AMOS campaigns linked the activity to an AMOS-family operation that had been active since late 2025. This established a broader operational timeframe for the malware family beyond isolated detections.

Dec 8, 20257mo ago

Kroll reports a new AMOS infection vector tied to AI-themed lures

Kroll published research describing a new infection vector for AMOS and highlighting risks associated with AI adoption-themed social engineering. The report marked a new documented delivery method for the macOS infostealer family.

Jan 11, 20242y ago

Atomic Stealer upgrade reported using encrypted payloads

A January 2024 report said Atomic Stealer for macOS had been updated to target Mac users with encrypted payloads. The disclosure marked a new technical development in the AMOS malware family beyond earlier reporting on its initial capabilities and malvertising distribution.

Atomic Stealer Gets an Upgrade - Targeting Mac Users with Encrypted Payload
Sep 6, 20233y ago

Atomic macOS Stealer delivered via malvertising campaign

Malwarebytes reported that Mac users were being targeted by a new malvertising campaign distributing Atomic macOS Stealer (AMOS). The report documented a new publicly disclosed delivery method for the malware family via malicious online advertising.

Mac users targeted in new malvertising campaign delivering Atomic Stealer
Apr 3, 20233y ago

Researchers disclose OSX.MacStealer targeting macOS users

Uptycs researchers disclosed a new macOS infostealer dubbed OSX.MacStealer that targets files, browser data, cryptocurrency wallets, and Apple Keychain data on macOS Catalina and newer systems. The malware was reported to spread via unsigned DMG files using social engineering and to exfiltrate stolen data to command-and-control infrastructure while sending summaries to Telegram.

Mar 1, 20233y ago

MacStealer is advertised as a macOS MaaS infostealer

A macOS information-stealing malware called MacStealer began being advertised on a dark web forum in early March as a malware-as-a-service offering priced at $100. The offering was described as still in early beta and lacking a builder or management panel.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

3 LINKEDOpen in app
Malware
1 linked
Affected products
1 linked
Macos
Organizations
1 linked
Malwarebytes
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

AMOS Mac Malware Spreads via Fake Ads and Trojanized macOS Downloads | Mallory