# Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)

> A malicious ad impersonating Claude Code sends victims to a fake Claude Code site that shows ClickFix-style instructions to paste a script into Terminal. The script installs Atomic macOS (AMOS) Stealer, which then prompts for the user's password and permissions. The incident was documented with a pcap on 2026-10-02 and fits a wider 2026 pattern of AI-developer-tool malvertising against macOS users.

- **Published:** 2026-10-02T00:00:00Z
- **Last reviewed:** 2026-10-02T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2916
- **ID:** TL-2026-2916
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 13 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-10-02 Malware-Traffic-Analysis.net published a DFIR write-up of an Atomic macOS (AMOS) Stealer infection that began with a malicious advertisement impersonating Claude Code. The documented chain is: (1) a malicious ad mimicking Claude Code branding, (2) a fraudulent website spoofing Claude Code, (3) ClickFix-style instructions that tell the user to run a command in Terminal, (4) execution of that command, which installs AMOS Stealer, and (5) a request for the system password and permission grants. The page includes five screenshots, a pcap (22.8 MB), malware files (1.3 MB) and an IOC list (2.7 KB). The three archives are password-protected and were not available for review. Specific domains, IPs and hashes for this exact incident are therefore not confirmed here.

This incident matches a series of 2026 campaigns that use the same lure pattern. Bitdefender (2026-03-11) documented fake 'Claude Code' Google Ads that led to fake documentation pages. These pages delivered ClickFix commands: on macOS a base64-decoded script piped to zsh that fetched a Mach-O backdoor to /tmp/helper, with extended attributes stripped by xattr -c, and on Windows an mshta.exe-launched HTA. The campaign abused a compromised advertiser account and its macOS payload showed anti-sandbox/anti-VM checks similar to AMOS. Moonlock Lab and AdGuard (2026-02-18) described ClickFix lures hosted on malicious claude.ai artifacts promoted by Google Ads and delivering the MacSync stealer, an AMOS-family variant. A May 2026 report put that campaign at 200+ malicious ads and 35+ compromised advertiser accounts. Cato Networks (2026-08-24) reported a fake OpenAI Codex ClickFix lure on Google Sites with iframe-hosted, OS- and path-gated content, delivering a payload suspected to be AMOS and noting that similar Claude Code campaigns exist. Whether the 2026-10-02 incident belongs to the same operators is not established by the available sources.

AMOS is a malware-as-a-service macOS infostealer, first identified in April 2023 and rented on Telegram for about $1,000 per month. Public analyses (Cyble, Moonlock, K7, Sophos) describe a fake system-preferences password prompt shown through osascript, with the password validated via dscl authonly. It then steals Keychain data, browser credentials, cookies, autofill and payment data, and cryptocurrency wallet data and extensions. The data is zipped and sent to the C2 by HTTP POST. The AMOS-family technique details above come from those public analyses and have not been confirmed against this incident's samples.

Defender priorities: treat any website instruction to paste a command into Terminal as hostile, including for developer tools. Hunt for curl-to-zsh/bash pipelines launched from Terminal, osascript password dialogs, dscl authonly calls, xattr -c on files in /tmp, and zip archives created in /tmp followed by outbound POSTs. Block or alert on sponsored-search landing pages that impersonate developer tools.

## MITRE ATT&CK

- T1583.008 Acquire Infrastructure: Malvertising
- T1036 Masquerading
- T1204.004 User Execution: Malicious Copy and Paste
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1059.002 Command and Scripting Interpreter: AppleScript
- T1140 Deobfuscate/Decode Files or Information
- T1553.001 Subvert Trust Controls: Gatekeeper Bypass
- T1497.001 Virtualization/Sandbox Evasion: System Checks
- T1056.002 Input Capture: GUI Input Capture
- T1555.001 Credentials from Password Stores: Keychain
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1539 Steal Web Session Cookie
- T1005 Data from Local System
- T1560.001 Archive Collected Data: Archive via Utility

## Sources

- [Atomic macOS (AMOS) Stealer Infection from Malicious Ad Impersonating Claude Code](https://www.malware-traffic-analysis.net/2026/10/02/index.html)
- [Windows and macOS Malware Spreads via Fake "Claude Code" Google Ads (Bitdefender)](https://www.bitdefender.com/en-us/blog/labs/fake-claude-code-google-ads-malware)
- [Hackers Are Using Claude Artifacts to Distribute macOS Malware (Moonlock Lab / AdGuard)](https://hackmag.com/news/claude-malware)
- [MacSync Stealer via Google Ads and Claude AI (Ciphers Security)](https://cipherssecurity.com/macsync-stealer-google-ads-claude-ai-mac/)
- [Cato CTRL: When Trust Becomes Payload in Fake Codex ClickFix Campaign](https://www.catonetworks.com/blog/cato-ctrl-when-trust-becomes-payload-in-fake-codex-clickfix-campaign/)
- [Mac malware campaign via fake OpenAI Codex ads (The Register)](https://www.theregister.com/a/5291899)
- [Fake OpenAI Codex download tricks macOS users into installing malware (Help Net Security)](https://www.helpnetsecurity.com/2026/08/25/fake-openai-codex-download-macos-users/)
- [Why AMOS matters: the macOS malware stealing data at scale (Sophos)](https://www.sophos.com/en-us/blog/why-amos-matters-the-macos-malware-stealing-data-at-scale)
- [Under the hood of the Atomic macOS stealer (AMOS) (Moonlock)](https://moonlock.com/atomic-macos-stealer)
- [AMOS macOS Stealer (K7 Labs)](https://labs.k7computing.com/index.php/amos-macos-stealer/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2916
