Atomic MacOS (AMOS) Stealer Infection via Fake "macOS Toolkit" Terminal Command — Threadlinqs Intelligence
As of 2026-08-02, Atomic MacOS (AMOS) Stealer Infection via Fake "macOS Toolkit" Terminal Command is a medium-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 36 indicators of compromise.
Threat ID: TL-2026-1813 · Severity: MEDIUM · Status: ACTIVE · Category: MALWARE
SANS ISC (Brad Duncan) documented a live, self-infected AMOS (Atomic macOS Stealer) infection chain distributed through a spoofed "macOS toolkit" website, getmacouscloud[.]com, that tricks victims
On 2026-07-31, SANS Internet Storm Center handler Brad Duncan deliberately infected a lab macOS host by following the lure at getmacouscloud[.]com, a fake "macOS toolkit" site that instructs visitors to open Terminal and paste a supplied command rather than download and run a signed application — a variant of the ClickFix (MITRE T1204.004, "Malicious Copy and Paste") social-engineering pattern that has become one of the dominant initial-access vectors for macOS infostealers since March 2025. The initial lure chain observed includes macostruecloud[.]xyz/?h=2f9548d041648a8030c040ae0e1e530b&z=304, getmacouscloud[.]com/?FSSbmnNdviEDE5S?io=16vwsb0rgIiPNIgM, and grove-89[.]com/api/metrics/run?event=pasted (a pasted-event telemetry beacon fired the moment the victim executes the pasted command). The pasted command retrieves a first-stage zsh script (SHA-256 b9ec3261d633c289e51c5fa8842af4350efe68446df39cb995de82e0941d0f3c, 1,973 bytes) from render65[.]com/curl/f5509695dd98a9732378e5256d6235415d64d92194459bb08525c7ce5991a0c9. That script contains a gzip-compressed, base64-encoded blob which, once deobfuscated, yields a second zsh script (SHA-256 13b868b3ea8b492e7fbab1ca04535c53d0930650185b5a082cd59c1974689cd5, 1,227 bytes, fetched from render65[.]com/2kqYRM0DCrnyJgoS4gVLl_FHJRRdTUhGCbjyuYwpZ6c/m1/update) responsible for downloading the actual AMOS payloads. Additional HTTPS traffic to macospheres[.]com was observed in the same session window.
The delivered malware consists of universal Mach-O binaries supporting both x86_64 and arm64 (Apple Silicon), first staged at /tmp/helper (297,952 bytes, SHA-256 9f25ec533cb23d020e568fb771500d7776b1300f07119ad9d0876f4329ce22ab) and then persisted as AccountsHelper (438,656 bytes, SHA-256 0a03cf18de28017c0ea591dffc380a6b41fedd2acc3a39e901e58d9188c01836) under ~/Library/Application Support/.com.apple.accountsd/ and as mdworker_shared (503,152 bytes, SHA-256 01a0d5332b09bb299f7784bf0d0c43c4199269ed6a0712377279eeb999847d20) under ~/Library/Application Support/.com.apple.metadata.mds/. Both persistence paths masquerade as legitimate Apple system services (accountsd, mdworker) inside hidden, dot-prefixed directories — MITRE T1036.005 (Masquerading: Match Legitimate Name or Location) combined with T1564.001 (Hide Artifacts: Hidden Files and Directories).
Once running, the stealer communicates over plaintext HTTP (TCP/80, no TLS) to the C2 server 188.166.78[.]138, hitting a broader set of REST-style endpoints than initially catalogued: /api/metrics/run?event=started&stage=boot, /api/metrics/run?event=stage&stage=init_session, /api/metrics/run?event=stage=messengers, /api/metrics/run?event=stage&stage=credentials, /api/metrics/run?event=stage&stage=browsers, /api/metrics/run?event=stage&stage=wallets, /api/metrics/run?event=stage&stage=resolve_auth, /api/metrics/run?event=stage&stage=local_data, /contact, /api/join/, /api/bots/device-info, /api/tasks/ack, /api/feed/register (all HTTP POST), plus /api/tasks/r3dqbX7fptIT-gXz--D_nw?v=2.1 and /api/feed/items/49359f77ebb4ffd9a95568d27a8ff3e7 (HTTP GET). This staged tasking model — boot, init_session, messengers, credentials, browsers, wallets, resolve_auth, local_data — is consistent with the broader AMOS/Atomic macOS Stealer malware-as-a-service (MaaS) family, first advertised on Telegram in April 2023 for roughly $3,000/month and historically associated with the handle "ping3r" and a suspected Go-source-path developer identity "iluhaboltov" (Ilya Boltov, per Cyble research). AMOS pioneered the current wave of macOS credential/crypto stealers; one of its developers, tracked as Rodrigo4, later forked the codebase into Poseidon Stealer, which was itself rebranded as Odyssey Stealer — all three families share overlapping TTPs (AppleScript-based credential prompts, Keychain extraction via a bundled "Chainbreaker" utility, browser cookie/session theft, and cryptocurrency wallet targeting).
The wider macOS infostealer ecosystem AMOS sits in has evolved substantia
Target sectors: consumer, cryptocurrency
Target regions: Global
Detections & IOCs
As of 2026-08-17, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 36 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, MEDIUM, threat intelligence, cybersecurity, T1583.001, T1583.006, T1204.004, T1059.004, T1059.002, T1543.004, T1543.004, T1140, T1027, T1027.010