Atomic MacOS Stealer (AMOS) distribution through AI-app lures, SEO poisoning, and supply-chain abuse
Malware Activity
Summary
Hide ▲
Show ▼
Atomic MacOS Stealer (AMOS) is being distributed to macOS users through ClickFix-style Terminal prompts that silently download, mount, and launch DMG payloads. In the latest 2026-06 activity, Palo Alto Networks Unit 42 observed victims being steered from a fake CAPTCHA page into running a malicious command that fetched s.01M0td.dmg from svs-verificationdate[.]beer, mounted it with hdiutil, and launched NNApp.app. on Mac devices.
Related Happenings
OkoBot Windows malware framework with SeedHunter wallet phrase theft
Malware Activity
H score31
First: 15.07.2026 18:30
Last: 15.07.2026 18:30
Sources 1
About this happening:
The OkoBot malware framework is actively running on Windows and using SeedHunter to steal hardware wallet recovery phrases, putting wallet owners and endpoint data at...
OkoBot Windows malware framework with SeedHunter wallet phrase theft
Malware ActivityAbout this happening: The OkoBot malware framework is actively running on Windows and using SeedHunter to steal hardware wallet recovery phrases, putting wallet owners and endpoint data at...
OkoBot hardware-wallet phrase theft campaign
Campaign
H score37
First: 15.07.2026 18:30
Last: 15.07.2026 18:30
Sources 1
About this happening:
An active OkoBot campaign is driving hundreds of victimizations across more than 25 countries, showing broad coordinated malware activity. The operation uses overlapping d...
OkoBot hardware-wallet phrase theft campaign
CampaignAbout this happening: An active OkoBot campaign is driving hundreds of victimizations across more than 25 countries, showing broad coordinated malware activity. The operation uses overlapping d...
CrashStealer meeting-PIN delivery campaign
Campaign
H score35
First: 13.07.2026 22:04
Last: 13.07.2026 22:04
Sources 1
About this happening:
The CrashStealer campaign is delivering a signed, Apple-notarized installer from a fake software site gated by a meeting PIN, narrowing infection opportunities to...
CrashStealer meeting-PIN delivery campaign
CampaignAbout this happening: The CrashStealer campaign is delivering a signed, Apple-notarized installer from a fake software site gated by a meeting PIN, narrowing infection opportunities to...
CrashStealer macOS information stealer activity
Malware Activity
H score10
First: 13.07.2026 20:36
Last: 13.07.2026 20:36
Sources 1
About this happening:
CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...
CrashStealer macOS information stealer activity
Malware ActivityAbout this happening: CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...
Codemado open-directory operator toolkit leak
Data Leak
H score18
First: 13.07.2026 18:30
Last: 13.07.2026 18:30
Sources 1
About this happening:
A misconfigured Budapest VPS exposed codemado's phishing toolkit, leaking session material and credential artifacts that could enable account hijacking. The readable direc...
Codemado open-directory operator toolkit leak
Data LeakAbout this happening: A misconfigured Budapest VPS exposed codemado's phishing toolkit, leaking session material and credential artifacts that could enable account hijacking. The readable direc...
Timeline
-
12.02.2026 16:25 8 articles · 5mo ago
AMOS distribution via AI-app lures and supply-chain abuse
Technical Analysis UpdateAtomic MacOS Stealer (AMOS) is being distributed to macOS users through AI-app lures, poisoned skill marketplaces, fraudulent GitHub repositories, SEO poisoning, malvertising, and ClickFix-style terminal prompts, with malicious installers and add-ons designed to steal credentials, browser sessions, crypto wallet data, SSH keys, PII, and other sensitive files.
Show sources
- AMOS infostealer targets macOS through a popular AI app — www.bleepingcomputer.com — 12.02.2026 16:25
- AMOS infostealer targets macOS through a popular AI app — www.bleepingcomputer.com — 12.02.2026 16:25
- Bing AI promoted fake OpenClaw GitHub repo pushing info-stealing malware — www.bleepingcomputer.com — 06.03.2026 00:37
- LastPass: Fake password managers infect Mac users with malware — www.bleepingcomputer.com — 22.09.2025 18:36
- Attackers Use Phony GitHub Pages to Deliver Mac Malware — www.darkreading.com — 22.09.2025 22:44
- VirusTotal Finds 44 Undetected SVG Files Used to Deploy Base64-Encoded Phishing Pages — thehackernews.com — 05.09.2025 09:13
- New macOS ClickFix attack silently mounts DMGs to push infostealer — www.bleepingcomputer.com — 23.06.2026 21:30
- ClickFix Now Cybercriminals' Favorite Malware Delivery Technique — www.infosecurity-magazine.com — 30.06.2026 15:00