Malware & Threats

Hundreds Targeted in New Atomic macOS Stealer Campaign

Between June and August, over 300 entities were targeted with the Atomic macOS Stealer via malvertising.

macOS malware

CrowdStrike warns of a spike in attacks aimed at infecting macOS users with a variant of the infamous Atomic macOS Stealer (AMOS) information stealer.

Between June and August, the cybercrime group Cookie Spider, which operates the AMOS malware-as-a-service (MaaS) enterprise, used malvertising to direct victims to fraudulent help websites and trick them into installing the malware.

The campaign, CrowdStrike says, targeted users who were searching for solutions to common macOS issues, and relied on promoting fraudulent advertisements for websites where victims were instructed to execute a malicious command on their systems.

The command would fetch a Bash script from a remote server, to capture the victim’s password and download an executable from another remote location.

Dubbed SHAMOS, the payload is a variant of AMOS that contains anti-VM checks to prevent execution in a sandboxed environment, and which can perform reconnaissance and data collection tasks.

The malware searches the system for files that contain credentials, data from Keychain, AppleNotes, browsers, and known cryptocurrency wallets, and attempts to exfiltrate them to a remote server, packed in a ZIP archive.

Advertisement. Scroll to continue reading.

Additionally, SHAMOS can download and execute payloads, including a botnet module and a fake Ledger Live wallet application.

The malvertising campaign targeted users in Canada, China, Colombia, Italy, Japan, Mexico, the US, the UK, and other countries, but was not served to Russian users.

CrowdStrike’s investigation revealed that the cybercriminals likely impersonated a legitimate Australia-based electronics store in their Google Advertising profile.

“This campaign underscores the popularity of malicious one-line installation commands among eCrime actors. This technique allows them to bypass Gatekeeper security checks and install the Mach-O executable directly onto victim devices,” CrowdStrike notes.

Related: Homebrew macOS Users Targeted With Information Stealer Malware

Related: High-Value NPM Developers Compromised in New Phishing Campaign

Related: North Korean Hackers Target macOS Users

Related: Digium Phones Targeted in Cybercrime Campaign Aimed at VoIP Systems

Related Content

Nation-State

The campaigns focus on financial organizations, including cryptocurrency, venture capital, and blockchain entities.

Malware & Threats

The hackers trick victims into accessing GitHub or GitLab repositories that are opened using Visual Studio Code.

Malware & Threats

The malware now uses a four-stage infection chain, has an additional persistence mechanism, and also targets Firefox browser data.

Malware & Threats

Threat actors rely on malicious GitHub repositories to infect LastPass’s macOS users with the Atomic infostealer.

Malware & Threats

macOS users are targeted with multiple versions of the ReaderUpdate malware written in Crystal, Nim, Rust, and Go programming languages.

Ransomware

New versions of the Albabat ransomware target Windows, Linux, and macOS, and retrieve configuration files from GitHub.

Malware & Threats

A recently identified macOS infostealer named FrigidStealer has been distributed through a compromised website, as a fake browser update.

Malware & Threats

Microsoft has observed a new variant of the XCSSET malware being used in limited attacks against macOS users.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version