Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activitysearch-ad-manipulationidentity-impersonation-fraudcybercrime-service-ecosystem

Weaponized DMG Installers Spread macOS Infostealers Including AMOS

Updated 6d agoFirst seen Jun 11, 20266 sources

Threat actors are increasingly using weaponized .dmg files disguised as legitimate macOS software installers to deliver infostealer malware, with campaigns relying heavily on social engineering to convince users to bypass Apple Gatekeeper and other trust prompts. Researchers said the malware typically focuses on rapid collection and exfiltration rather than persistence, stealing browser credentials, cookies, authentication tokens, Apple Keychain data, macOS passwords, and cryptocurrency wallet information from infected systems.

Multiple macOS stealer families have been tied to the tactic, including Atomic macOS Stealer (AMOS), Poseidon, Odyssey, and MacSync. AMOS in particular has been marketed as malware-as-a-service and distributed through malvertising, SEO poisoning, fake download pages, social media ads, GitHub-hosted binaries, open directories, poisoned search results, and piracy forums while impersonating popular apps such as Notion, Trello, Arc, Slack, Todoist, and CleanMyMac X. Defenders were urged to monitor suspicious DMG mount activity in /Volumes, inspect hidden .background directories, use OCR on installer graphics, unmount suspicious disk images quickly, and restrict software installation to legitimate, Apple-verified sources outside unofficial or cracked-software channels.

Share:
Weaponized DMG Installers Spread macOS Infostealers Including AMOS
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Jun 16, 20267d ago

CyberProof reports renewed AMOS campaigns targeting Keychain and developer files

CyberProof reported renewed Atomic macOS Stealer activity in financially motivated campaigns using deceptive software downloads, fake websites, and social-engineering lures. The report said AMOS used native macOS tools to steal browser data, the macOS Keychain database, and developer files, then exfiltrated the data via HTTP PUT to bestbuydomain.com with retry and cleanup logic.

Amos Stealer Targets macOS Keychain Files and Browser Passwords
Jun 11, 202611d ago

macOS infostealers dominate newly reported malware in 2025

Huntress reported that in 2025, more than 65% of newly reported macOS malware was classified as infostealers. The finding reflects a shift toward treating Apple systems as high-value targets for credential and wallet theft.

Hackers Use Weaponized DMG Files to Target macOS Users With Infostealer Malware - Cyber Security News
Jan 1, 20266mo ago

Cyble first reports Atomic macOS Stealer (AMOS)

Sophos states that Atomic macOS Stealer was first reported by Cyble in April 2023. AMOS was described as a macOS infostealer sold via Telegram as malware-as-a-service.

Atomic macOS Stealer leads sensitive data theft on macOS | SOPHOS
Jun 1, 20233y ago

Bitdefender identifies new Atomic Stealer variant in the wild

Bitdefender reported a new and largely undetected macOS variant of Atomic Stealer (AMOS) found in malicious DMG files. The company detailed its Python-and-AppleScript theft chain, browser and wallet targeting, C2 endpoint, and said code similarities with RustDoor supported prior attribution of AMOS to a Russian threat actor.

When Stealers Converge: New Variant of Atomic Stealer in the Wild
May 3, 20233y ago

SentinelOne documents Atomic Stealer variants sold via Telegram

SentinelOne published analysis of Atomic Stealer (AMOS), a macOS infostealer marketed on Telegram for $1,000 per month. The report described multiple variants, AppleScript-based credential theft, targeted browser and wallet data, and related infrastructure and indicators.

Atomic Stealer: New Variant of macOS Malware on Telegram
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

63 LINKEDOpen in app
Affected products
22 linked
MacosApplescriptWindowsFirefoxNotionChromeTodoistTor BrowserElectrumGithubCleanmymac XSafariBrave BrowserPhotoshop CcIphoneTerminalOperaChromiumVmwareMicrosoft OfficeIosSentinelone
Organizations
26 linked
AppleGoogleMicrosoft CorporationCyberProofHackread.comBinanceNotionXSalesforceThe Browser CompanyDoistCybleAtlassianLinkedinRed CanaryGitHubAdobeHuntressCyber Security NewsSentinelOneSophosBitdefenderCoinomiMacpawExodus MovementMachine Box
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.