AMOS

Malware

⚠️ Overview

AMOS (Atomic macOS Stealer) is a macOS-specific information-stealing malware first documented in April 2023 by the SentinelOne threat research team. It is operated as a malware-as-a-service (MaaS) by an actor known as "Rodian" and is classified as a stealer targeting macOS users, primarily to harvest credentials, crypto wallets, and sensitive files.

🔧 Technical Capabilities

AMOS propagates via phishing emails and malicious websites posing as legitimate software downloads (e.g., cracked apps or browser updates). Its primary attack vector is a single Mach-O binary that when executed prompts the user for a system password via a fake macOS authentication dialog. Once granted, the malware collects iCloud Keychain passwords, browser cookies and saved credentials from Safari, Chrome, and Firefox, cryptocurrency wallet data (e.g., from MetaMask, Electrum, Atomic Wallet), and system file content from ~/Documents and ~/Desktop. It exfiltrates data over HTTPS to a command-and-control (C2) server using a custom API endpoint and does not implement persistence mechanisms, relying on one-time execution. Evasion techniques include obfuscation of strings and anti-analysis checks for sandboxes or debuggers (e.g., checking for the presence of Xcode tools).

📜 History & Notable Incidents

First publicly reported in April 2023 via a SentinelOne blog post (https://www.sentinelone.com/blog/atomic-macos-stealer-amos/), AMOS quickly became widely advertised on Russian-language cybercrime forums. In September 2023, researchers tied AMOS to a campaign distributing fake "CryptoGate" and "Ledger Live" applications targeting cryptocurrency investors. No CVEs are directly associated; the malware exploits user social engineering rather than system vulnerabilities. Law enforcement has not taken public action against the operators as of 2025.

🔍 Detection Indicators

Known file hashes include SHA-256: 5f1c8a1e2b... (varies per sample); behavioral signatures include a request to the URL pattern /api/store/ on the C2 domain (e.g., amos-[random].xyz). Network IOCs include HTTPS POST requests to endpoints like /api/v2/collect with User-Agent strings such as "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36". No specific registry keys or mutex names exist since macOS uses plist files; however, the binary often masquerades as "Install" or "Update".

☠️ Risk & Impact

AMOS causes direct financial loss by exfiltrating cryptocurrency wallet private keys and passwords, leading to theft of digital assets. It also compromises personal and corporate credentials, enabling account takeovers and potential lateral movement in enterprise environments with macOS devices. The primary affected sectors are cryptocurrency investors and technology professionals, though any macOS user is at risk.

🛡️ Mitigation

Mitigation includes using application allowlisting (e.g., macOS Gatekeeper), disabling the "Allow apps from anywhere" setting, and deploying endpoint detection rules (e.g., SentinelOne EDR or CrowdStrike Falcon) that flag Mach-O binaries requesting Keychain access after a fake password prompt. Regularly backing up cryptocurrency wallets offline and avoiding downloads from untrusted sources are also critical defenses.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.