Quick Facts
- AMOS malware detections jumped 300% in a single month, with macOS infostealers increasing 101% between Q4 2023 and Q4 2024
- The malware now includes a backdoor that survives reboots and enables remote command execution on infected Macs
- AMOS has infected thousands of machines across 120 countries, with hackers selling access for $1,000-$3,000 monthly subscriptions
The Atomic macOS Stealer (AMOS) received a major upgrade in 2025 that transforms it from a data theft tool into a platform for long-term system compromise. Moonlock Lab, MacPaw’s cybersecurity division, confirmed the malware now installs a hidden backdoor that gives attackers remote access to devices long after the initial breach.
The upgrade marks a significant escalation in macOS threats. AMOS detections spiked roughly 300% in a single month, according to security researchers. MacOS infostealers overall increased 101% between the last two quarters of 2024.
“The combination of a plug-and-play stealer with backdoor functionality not only raises the technical sophistication of the group but also significantly increases the risk to victims,” Moonlock Lab warned. “It turns a one-time breach into a long-term compromise.”
AMOS operates as malware-as-a-service, with developers selling monthly subscriptions between $1,000 and $3,000 on hacker forums and Telegram. The malware has infected thousands of machines across more than 120 countries, with the United States, France, Italy, the United Kingdom, and Canada among the most affected.
The malware steals credentials, browser data, cryptocurrency wallets, Telegram chats, VPN profiles, keychain items, Apple Notes, and files from common folders. Security experts note that AMOS primarily targets macOS users in technology, design, and cryptocurrency sectors.
Hackers distribute AMOS through fake Homebrew download websites and malvertising campaigns disguised as Microsoft Teams downloads. Recent campaigns use “ClickFix” methodologies that trick users into executing malicious code through paste-and-run techniques.
Darktrace analysts observed AMOS campaigns across 24 countries, detecting activity at multiple stages of the attack chain. One prominent affiliate known as “Baptist” targeted victims through Google Ads and sold stolen data logs to other cybercriminals.
“The old comfort phrase, that ‘Macs don’t get malware’ is now more of a historical quote than a safety rule,” security professionals noted. “macOS has moved from a niche option for cybercrime to the main course.”
Apple responded with macOS Sequoia, which blocks attempts to install malicious or unsigned .dmg files by default. However, security researchers warn that AMOS represents a fundamental shift in the Mac threat landscape as cybercriminals increasingly view Apple users as profitable targets.
The AMOS family has expanded into multiple variants developed by competing criminal teams, including Banshee, Cthulu, Poseidon, and RodrigoStealer. These variants employ sophisticated evasion techniques like AppleScript-based password harvesting and XOR-obfuscated payloads.
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
