Fake 'macOS Toolkit' Sites Spreading AMOS Stealer Malware
Security researchers at Unit 42 have published a fresh look at Atomic macOS (AMOS) stealer, a well-known information-stealing malware targeting Apple computers. First advertised on Telegram in April 2024, AMOS stealer has grown into one of the most common macOS threats, capable of harvesting saved passwords, browser data and cryptocurrency wallet details.
In this latest case, attackers set up a website posing as an installation guide for a 'macOS toolkit'. Victims are told to copy and paste a command into the Terminal app, a technique similar to the well-known ClickFix scam but using a slightly different delivery method. Once run, the command downloads a script that fetches a compressed, encoded payload, ultimately installing the AMOS stealer on the victim's Mac.
The malware continues to be spread through multiple channels, including malicious advertising and fake offers of cracked, copyright-protected software. Because AMOS stealer's specific web addresses and files change frequently, defenders should focus on the underlying behaviour rather than any single indicator: unsolicited instructions asking users to paste commands into Terminal or a Run window should always be treated as a red flag.
Key Takeaway: Train staff never to copy and paste commands into Terminal or Run windows from websites, even ones claiming to help install software, as this is a common way attackers deliver macOS malware.