Atomic macOS (AMOS) Stealer Activity

    Date: 09/17/2026

    Severity: High

    Summary

    AMOS Stealer is a macOS information stealer advertised on Telegram as early as April 2024 and remains a growing threat. It steals system information, credentials, and sensitive data from web browsers, cryptocurrency wallets, and other applications. AMOS has been distributed through ClickFix campaigns, malicious advertisements, and websites offering cracked versions of popular software. These sites use fake installation instructions, such as a supposed macOS toolkit, to trick users into installing the malware. This analysis examines an AMOS Stealer infection observed on August 5, 2026, delivered through a page promoting a fake “macOS toolkit.”

    Indicators of Compromise (IOC) List     

    Domain/URLs

    https://getmacouscloud.com

    https://ferncore13.com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688

    https://grove-89.com/api/metrics/run?event=pasted

    https://ferncore13.com/2kqYRM0DCrnyJgoS4gVLl_FHJRRdTUhGCbjyuYwpZ6c/m1/update

    Hash

    71781ad8adefb499aee9bcbe1a166e69ccc37a47066682f617d65c76d8cde88c

    7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ffd3d1c154d40d7ca3a

    a598fcdcd49247312861ff90c16cb4a5d49fede6072e30e7416dd276668fa2a9

    6bfcdb4920383375b7e519918df7eb4db751b974b5571a15ce66b82478012620

    4504006d1911057be42435d4625f03d83c4d0b7b6898d14beb9cdeba6cf667b9

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "https://grove-89.com/api/metrics/run?event=pasted" or url like "https://grove-89.com/api/metrics/run?event=pasted" or siteurl like "https://grove-89.com/api/metrics/run?event=pasted" or domainname like "https://ferncore13.com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688" or url like "https://ferncore13.com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688" or siteurl like "https://ferncore13.com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688" or domainname like "https://ferncore13.com/2kqYRM0DCrnyJgoS4gVLl_FHJRRdTUhGCbjyuYwpZ6c/m1/update" or url like "https://ferncore13.com/2kqYRM0DCrnyJgoS4gVLl_FHJRRdTUhGCbjyuYwpZ6c/m1/update" or siteurl like "https://ferncore13.com/2kqYRM0DCrnyJgoS4gVLl_FHJRRdTUhGCbjyuYwpZ6c/m1/update" or domainname like "https://getmacouscloud.com" or url like "https://getmacouscloud.com" or siteurl like "https://getmacouscloud.com"

    Detection Query 2 :

    sha256hash IN ("4504006d1911057be42435d4625f03d83c4d0b7b6898d14beb9cdeba6cf667b9","71781ad8adefb499aee9bcbe1a166e69ccc37a47066682f617d65c76d8cde88c","7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ffd3d1c154d40d7ca3a","6bfcdb4920383375b7e519918df7eb4db751b974b5571a15ce66b82478012620","a598fcdcd49247312861ff90c16cb4a5d49fede6072e30e7416dd276668fa2a9")

    Reference: 

    https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/         


    Tags

    MalwareStealerTelegramcryptocurrencyCredential HarvestingClickFix

    « Previous Article

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags