Date: 09/17/2026
Severity: High
Summary
AMOS Stealer is a macOS information stealer advertised on Telegram as early as April 2024 and remains a growing threat. It steals system information, credentials, and sensitive data from web browsers, cryptocurrency wallets, and other applications. AMOS has been distributed through ClickFix campaigns, malicious advertisements, and websites offering cracked versions of popular software. These sites use fake installation instructions, such as a supposed macOS toolkit, to trick users into installing the malware. This analysis examines an AMOS Stealer infection observed on August 5, 2026, delivered through a page promoting a fake “macOS toolkit.”
Indicators of Compromise (IOC) List
Domain/URLs | https://getmacouscloud.com https://ferncore13.com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688 https://grove-89.com/api/metrics/run?event=pasted https://ferncore13.com/2kqYRM0DCrnyJgoS4gVLl_FHJRRdTUhGCbjyuYwpZ6c/m1/update |
Hash | 71781ad8adefb499aee9bcbe1a166e69ccc37a47066682f617d65c76d8cde88c
7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ffd3d1c154d40d7ca3a
a598fcdcd49247312861ff90c16cb4a5d49fede6072e30e7416dd276668fa2a9
6bfcdb4920383375b7e519918df7eb4db751b974b5571a15ce66b82478012620
4504006d1911057be42435d4625f03d83c4d0b7b6898d14beb9cdeba6cf667b9
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "https://grove-89.com/api/metrics/run?event=pasted" or url like "https://grove-89.com/api/metrics/run?event=pasted" or siteurl like "https://grove-89.com/api/metrics/run?event=pasted" or domainname like "https://ferncore13.com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688" or url like "https://ferncore13.com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688" or siteurl like "https://ferncore13.com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688" or domainname like "https://ferncore13.com/2kqYRM0DCrnyJgoS4gVLl_FHJRRdTUhGCbjyuYwpZ6c/m1/update" or url like "https://ferncore13.com/2kqYRM0DCrnyJgoS4gVLl_FHJRRdTUhGCbjyuYwpZ6c/m1/update" or siteurl like "https://ferncore13.com/2kqYRM0DCrnyJgoS4gVLl_FHJRRdTUhGCbjyuYwpZ6c/m1/update" or domainname like "https://getmacouscloud.com" or url like "https://getmacouscloud.com" or siteurl like "https://getmacouscloud.com" |
Detection Query 2 : | sha256hash IN ("4504006d1911057be42435d4625f03d83c4d0b7b6898d14beb9cdeba6cf667b9","71781ad8adefb499aee9bcbe1a166e69ccc37a47066682f617d65c76d8cde88c","7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ffd3d1c154d40d7ca3a","6bfcdb4920383375b7e519918df7eb4db751b974b5571a15ce66b82478012620","a598fcdcd49247312861ff90c16cb4a5d49fede6072e30e7416dd276668fa2a9")
|
Reference:
https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/