Threat reportMalwareTL-2026-2916

Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)

highACTIVE

Atomic macOS (AMOS) Stealer Delivered via Malicious Ad (TL-2026-2916), also tracked as Atomic Stealer, is a high-severity malware campaign, first published 2026-10-02. It has no confirmed attribution, affects Apple macOS, maps to 14 MITRE ATT&CK techniques (T1005, T1036, T1056.002), and is covered by 9 detection rules and 13 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
14MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
13Indicators of compromise

Key facts for TL-2026-2916

Threat ID
TL-2026-2916
Also known as
Atomic Stealer, AMOS, Fake Claude Code ClickFix malvertising
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, software-development, cryptocurrency, general-consumer
Target regions
Global
Detection rules
9
Indicators of compromise
13

Malware and tooling in Atomic macOS (AMOS) Stealer Delivered via Malicious Ad

Malware and tooling: AMOS, MacSync Stealer

How Atomic macOS (AMOS) Stealer Delivered via Malicious Ad works

A malicious ad impersonating Claude Code sends victims to a fake Claude Code site that shows ClickFix-style instructions to paste a script into Terminal. The script installs Atomic macOS (AMOS) Stealer, which then prompts for the user's password and permissions. The incident was documented with a pcap on 2026-10-02 and fits a wider 2026 pattern of AI-developer-tool malvertising against macOS users.

On 2026-10-02 Malware-Traffic-Analysis.net published a DFIR write-up of an Atomic macOS (AMOS) Stealer infection that began with a malicious advertisement impersonating Claude Code. The documented chain is: (1) a malicious ad mimicking Claude Code branding, (2) a fraudulent website spoofing Claude Code, (3) ClickFix-style instructions that tell the user to run a command in Terminal, (4) execution of that command, which installs AMOS Stealer, and (5) a request for the system password and permission grants. The page includes five screenshots, a pcap (22.8 MB), malware files (1.3 MB) and an IOC list (2.7 KB). The three archives are password-protected and were not available for review. Specific domains, IPs and hashes for this exact incident are therefore not confirmed here.

This incident matches a series of 2026 campaigns that use the same lure pattern. Bitdefender (2026-03-11) documented fake 'Claude Code' Google Ads that led to fake documentation pages. These pages delivered ClickFix commands: on macOS a base64-decoded script piped to zsh that fetched a Mach-O backdoor to /tmp/helper, with extended attributes stripped by xattr -c, and on Windows an mshta.exe-launched HTA. The campaign abused a compromised advertiser account and its macOS payload showed anti-sandbox/anti-VM checks similar to AMOS. Moonlock Lab and AdGuard (2026-02-18) described ClickFix lures hosted on malicious claude.ai artifacts promoted by Google Ads and delivering the MacSync stealer, an AMOS-family variant. A May 2026 report put that campaign at 200+ malicious ads and 35+ compromised advertiser accounts. Cato Networks (2026-08-24) reported a fake OpenAI Codex ClickFix lure on Google Sites with iframe-hosted, OS- and path-gated content, delivering a payload suspected to be AMOS and noting that similar Claude Code campaigns exist. Whether the 2026-10-02 incident belongs to the same operators is not established by the available sources.

AMOS is a malware-as-a-service macOS infostealer, first identified in April 2023 and rented on Telegram for about $1,000 per month. Public analyses (Cyble, Moonlock, K7, Sophos) describe a fake system-preferences password prompt shown through osascript, with the password validated via dscl authonly. It then steals Keychain data, browser credentials, cookies, autofill and payment data, and cryptocurrency wallet data and extensions. The data is zipped and sent to the C2 by HTTP POST. The AMOS-family technique details above come from those public analyses and have not been confirmed against this incident's samples.

Defender priorities: treat any website instruction to paste a command into Terminal as hostile, including for developer tools. Hunt for curl-to-zsh/bash pipelines launched from Terminal, osascript password dialogs, dscl authonly calls, xattr -c on files in /tmp, and zip archives created in /tmp followed by outbound POSTs. Block or alert on sponsored-search landing pages that impersonate developer tools.

MITRE ATT&CK techniques used in TL-2026-2916

Collection

T1005 Data from Local System; T1560.001 Archive Collected Data: Archive via Utility

Defense Evasion

T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1497.001 Virtualization/Sandbox Evasion: System Checks

Credential Access

T1056.002 Input Capture: GUI Input Capture; T1539 Steal Web Session Cookie; T1555.001 Credentials from Password Stores: Keychain; T1555.003 Credentials from Password Stores: Credentials from Web Browsers

Execution

T1059.002 Command and Scripting Interpreter: AppleScript; T1059.004 Command and Scripting Interpreter: Unix Shell; T1204.004 User Execution: Malicious Copy and Paste

defense-impairment

T1553.001 Subvert Trust Controls: Gatekeeper Bypass

Resource Development

T1583.008 Acquire Infrastructure: Malvertising

Affected products and versions in Atomic macOS (AMOS) Stealer Delivered via Malicious Ad

  • Apple — macOS
    Vulnerable versions: Users who execute the pasted Terminal command (social-engineering based; no software vulnerability)

Remediation for Atomic macOS (AMOS) Stealer Delivered via Malicious Ad

Immediate actions

  • Do not paste or run Terminal commands from websites or ads, including pages that claim to be Claude Code or other developer-tool installers
  • On any Mac where such a command was run: isolate the host, rotate the macOS account password, and rotate all credentials, session cookies and API/SSH keys stored in browsers and Keychain
  • Move cryptocurrency wallet funds to new wallets created on a clean device
  • Hunt for curl-to-zsh/bash pipelines, osascript password prompts, dscl authonly calls, xattr -c on files in /tmp, and zip archives followed by outbound POSTs

Workarounds

  • Use MDM controls to restrict unsigned or unnotarized binary execution
  • Use DNS/web filtering to block known ClickFix and malvertising infrastructure

Longer-term hardening

  • Install Claude Code only from Anthropic's official documentation and package channels, and bookmark the official URL instead of using sponsored search results
  • Deploy macOS EDR with behavioral detection for script-to-Terminal execution and Keychain access
  • Train developers on ClickFix-style lures and malvertising for AI developer tools
  • Block or monitor newly registered and look-alike domains and ad-landing pages impersonating developer tooling

Timeline of Atomic macOS (AMOS) Stealer Delivered via Malicious Ad

  • Atomic macOS Stealer (AMOS) first identified as a macOS infostealer sold as malware-as-a-service on Telegram (about $1,000/month).
  • Moonlock Lab and AdGuard report ClickFix lures hosted on malicious Claude artifacts, promoted by Google Ads, delivering the MacSync (AMOS-family) stealer.
  • Bitdefender publishes research on fake 'Claude Code' Google Ads leading to ClickFix pages that deliver a Windows stealer and a macOS Mach-O backdoor.
  • Reporting on the MacSync campaign cites 200+ malicious Google Ads, 35+ compromised advertiser accounts and 15,600+ views of malicious Claude artifacts.
  • Cato Networks reports a fake OpenAI Codex ClickFix campaign on Google Sites delivering a payload suspected to be AMOS, and notes similar Claude Code campaigns.
  • Malware-Traffic-Analysis.net publishes an AMOS Stealer infection that started from a malicious ad impersonating Claude Code, with pcap, malware files and IOC list.

Sources cited for Atomic macOS (AMOS) Stealer Delivered via Malicious Ad

Detection coverage for TL-2026-2916

As of 2026-10-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2916 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
13 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats