Atomic macOS (AMOS) Stealer Activity

Executive Summary

Unit 42 reports on Atomic macOS (AMOS), a modern macOS stealer that uses deceptive setup guides to harvest credentials and sensitive data. The malware disguises itself as legitimate installers, luring users into downloading and executing it. The post outlines detection techniques and mitigation steps to identify and block AMOS activity.


Intelligence Metadata - Source Publisher: Unit 42 (Palo Alto) - Published Date: 2026-09-16T10:00:06+00:00 - Category: research

Original Description: Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42.

"In all chaos there is a cosmos, in all disorder a secret order."

— Carl Jung
Source: Unit 42 (Palo Alto)