Threat reportMalwareTL-2026-2916
Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)
Atomic macOS (AMOS) Stealer Delivered via Malicious Ad (TL-2026-2916), also tracked as Atomic Stealer, is a high-severity malware campaign, first published 2026-10-02. It has no confirmed attribution, affects Apple macOS, maps to 14 MITRE ATT&CK techniques (T1005, T1036, T1056.002), and is covered by 9 detection rules and 13 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 14MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 13Indicators of compromise
Key facts for TL-2026-2916
- Threat ID
- TL-2026-2916
- Also known as
- Atomic Stealer, AMOS, Fake Claude Code ClickFix malvertising
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, cryptocurrency, general-consumer
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 13
Malware and tooling in Atomic macOS (AMOS) Stealer Delivered via Malicious Ad
Malware and tooling: AMOS, MacSync Stealer
How Atomic macOS (AMOS) Stealer Delivered via Malicious Ad works
A malicious ad impersonating Claude Code sends victims to a fake Claude Code site that shows ClickFix-style instructions to paste a script into Terminal. The script installs Atomic macOS (AMOS) Stealer, which then prompts for the user's password and permissions. The incident was documented with a pcap on 2026-10-02 and fits a wider 2026 pattern of AI-developer-tool malvertising against macOS users.
On 2026-10-02 Malware-Traffic-Analysis.net published a DFIR write-up of an Atomic macOS (AMOS) Stealer infection that began with a malicious advertisement impersonating Claude Code. The documented chain is: (1) a malicious ad mimicking Claude Code branding, (2) a fraudulent website spoofing Claude Code, (3) ClickFix-style instructions that tell the user to run a command in Terminal, (4) execution of that command, which installs AMOS Stealer, and (5) a request for the system password and permission grants. The page includes five screenshots, a pcap (22.8 MB), malware files (1.3 MB) and an IOC list (2.7 KB). The three archives are password-protected and were not available for review. Specific domains, IPs and hashes for this exact incident are therefore not confirmed here.
This incident matches a series of 2026 campaigns that use the same lure pattern. Bitdefender (2026-03-11) documented fake 'Claude Code' Google Ads that led to fake documentation pages. These pages delivered ClickFix commands: on macOS a base64-decoded script piped to zsh that fetched a Mach-O backdoor to /tmp/helper, with extended attributes stripped by xattr -c, and on Windows an mshta.exe-launched HTA. The campaign abused a compromised advertiser account and its macOS payload showed anti-sandbox/anti-VM checks similar to AMOS. Moonlock Lab and AdGuard (2026-02-18) described ClickFix lures hosted on malicious claude.ai artifacts promoted by Google Ads and delivering the MacSync stealer, an AMOS-family variant. A May 2026 report put that campaign at 200+ malicious ads and 35+ compromised advertiser accounts. Cato Networks (2026-08-24) reported a fake OpenAI Codex ClickFix lure on Google Sites with iframe-hosted, OS- and path-gated content, delivering a payload suspected to be AMOS and noting that similar Claude Code campaigns exist. Whether the 2026-10-02 incident belongs to the same operators is not established by the available sources.
AMOS is a malware-as-a-service macOS infostealer, first identified in April 2023 and rented on Telegram for about $1,000 per month. Public analyses (Cyble, Moonlock, K7, Sophos) describe a fake system-preferences password prompt shown through osascript, with the password validated via dscl authonly. It then steals Keychain data, browser credentials, cookies, autofill and payment data, and cryptocurrency wallet data and extensions. The data is zipped and sent to the C2 by HTTP POST. The AMOS-family technique details above come from those public analyses and have not been confirmed against this incident's samples.
Defender priorities: treat any website instruction to paste a command into Terminal as hostile, including for developer tools. Hunt for curl-to-zsh/bash pipelines launched from Terminal, osascript password dialogs, dscl authonly calls, xattr -c on files in /tmp, and zip archives created in /tmp followed by outbound POSTs. Block or alert on sponsored-search landing pages that impersonate developer tools.
MITRE ATT&CK techniques used in TL-2026-2916
Collection
T1005 Data from Local System; T1560.001 Archive Collected Data: Archive via Utility
Defense Evasion
T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1497.001 Virtualization/Sandbox Evasion: System Checks
Credential Access
T1056.002 Input Capture: GUI Input Capture; T1539 Steal Web Session Cookie; T1555.001 Credentials from Password Stores: Keychain; T1555.003 Credentials from Password Stores: Credentials from Web Browsers
Execution
T1059.002 Command and Scripting Interpreter: AppleScript; T1059.004 Command and Scripting Interpreter: Unix Shell; T1204.004 User Execution: Malicious Copy and Paste
defense-impairment
T1553.001 Subvert Trust Controls: Gatekeeper Bypass
Resource Development
Affected products and versions in Atomic macOS (AMOS) Stealer Delivered via Malicious Ad
- Apple — macOS
Vulnerable versions: Users who execute the pasted Terminal command (social-engineering based; no software vulnerability)
Remediation for Atomic macOS (AMOS) Stealer Delivered via Malicious Ad
Immediate actions
- Do not paste or run Terminal commands from websites or ads, including pages that claim to be Claude Code or other developer-tool installers
- On any Mac where such a command was run: isolate the host, rotate the macOS account password, and rotate all credentials, session cookies and API/SSH keys stored in browsers and Keychain
- Move cryptocurrency wallet funds to new wallets created on a clean device
- Hunt for curl-to-zsh/bash pipelines, osascript password prompts, dscl authonly calls, xattr -c on files in /tmp, and zip archives followed by outbound POSTs
Workarounds
- Use MDM controls to restrict unsigned or unnotarized binary execution
- Use DNS/web filtering to block known ClickFix and malvertising infrastructure
Longer-term hardening
- Install Claude Code only from Anthropic's official documentation and package channels, and bookmark the official URL instead of using sponsored search results
- Deploy macOS EDR with behavioral detection for script-to-Terminal execution and Keychain access
- Train developers on ClickFix-style lures and malvertising for AI developer tools
- Block or monitor newly registered and look-alike domains and ad-landing pages impersonating developer tooling
Timeline of Atomic macOS (AMOS) Stealer Delivered via Malicious Ad
- Atomic macOS Stealer (AMOS) first identified as a macOS infostealer sold as malware-as-a-service on Telegram (about $1,000/month).
- Moonlock Lab and AdGuard report ClickFix lures hosted on malicious Claude artifacts, promoted by Google Ads, delivering the MacSync (AMOS-family) stealer.
- Bitdefender publishes research on fake 'Claude Code' Google Ads leading to ClickFix pages that deliver a Windows stealer and a macOS Mach-O backdoor.
- Reporting on the MacSync campaign cites 200+ malicious Google Ads, 35+ compromised advertiser accounts and 15,600+ views of malicious Claude artifacts.
- Cato Networks reports a fake OpenAI Codex ClickFix campaign on Google Sites delivering a payload suspected to be AMOS, and notes similar Claude Code campaigns.
- Malware-Traffic-Analysis.net publishes an AMOS Stealer infection that started from a malicious ad impersonating Claude Code, with pcap, malware files and IOC list.
Sources cited for Atomic macOS (AMOS) Stealer Delivered via Malicious Ad
- Atomic macOS (AMOS) Stealer Infection from Malicious Ad Impersonating Claude Code
- Windows and macOS Malware Spreads via Fake "Claude Code" Google Ads (Bitdefender)
- Hackers Are Using Claude Artifacts to Distribute macOS Malware (Moonlock Lab / AdGuard)
- MacSync Stealer via Google Ads and Claude AI (Ciphers Security)
- Cato CTRL: When Trust Becomes Payload in Fake Codex ClickFix Campaign
- Mac malware campaign via fake OpenAI Codex ads (The Register)
- Fake OpenAI Codex download tricks macOS users into installing malware (Help Net Security)
- Why AMOS matters: the macOS malware stealing data at scale (Sophos)
- Under the hood of the Atomic macOS stealer (AMOS) (Moonlock)
- AMOS macOS Stealer (K7 Labs)
Detection coverage for TL-2026-2916
As of 2026-10-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2916 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.