Find notable cyber news and cases, enriched with sources, timelines, and signals.

Atomic MacOS Stealer (AMOS) distribution through AI-app lures, SEO poisoning, and supply-chain abuse

Malware Activity
First reported
Last updated
Happening score
H score 31
4 unique sources, 7 articles

Summary

Hide ▲

Atomic MacOS Stealer (AMOS) is being distributed to macOS users through ClickFix-style Terminal prompts that silently download, mount, and launch DMG payloads. In the latest 2026-06 activity, Palo Alto Networks Unit 42 observed victims being steered from a fake CAPTCHA page into running a malicious command that fetched s.01M0td.dmg from svs-verificationdate[.]beer, mounted it with hdiutil, and launched NNApp.app. on Mac devices.

Related Happenings

OkoBot Windows malware framework with SeedHunter wallet phrase theft

Malware Activity
H score31 First: 15.07.2026 18:30 Last: 15.07.2026 18:30 Sources 1

About this happening: The OkoBot malware framework is actively running on Windows and using SeedHunter to steal hardware wallet recovery phrases, putting wallet owners and endpoint data at...

OkoBot hardware-wallet phrase theft campaign

Campaign
H score37 First: 15.07.2026 18:30 Last: 15.07.2026 18:30 Sources 1

About this happening: An active OkoBot campaign is driving hundreds of victimizations across more than 25 countries, showing broad coordinated malware activity. The operation uses overlapping d...

CrashStealer meeting-PIN delivery campaign

Campaign
H score35 First: 13.07.2026 22:04 Last: 13.07.2026 22:04 Sources 1

About this happening: The CrashStealer campaign is delivering a signed, Apple-notarized installer from a fake software site gated by a meeting PIN, narrowing infection opportunities to...

CrashStealer macOS information stealer activity

Malware Activity
H score10 First: 13.07.2026 20:36 Last: 13.07.2026 20:36 Sources 1

About this happening: CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...

Codemado open-directory operator toolkit leak

Data Leak
H score18 First: 13.07.2026 18:30 Last: 13.07.2026 18:30 Sources 1

About this happening: A misconfigured Budapest VPS exposed codemado's phishing toolkit, leaking session material and credential artifacts that could enable account hijacking. The readable direc...

Timeline

  1. 12.02.2026 16:25 8 articles · 5mo ago

    AMOS distribution via AI-app lures and supply-chain abuse

    Technical Analysis Update

    Atomic MacOS Stealer (AMOS) is being distributed to macOS users through AI-app lures, poisoned skill marketplaces, fraudulent GitHub repositories, SEO poisoning, malvertising, and ClickFix-style terminal prompts, with malicious installers and add-ons designed to steal credentials, browser sessions, crypto wallet data, SSH keys, PII, and other sensitive files.

    Show sources