Info Stealing
macOS
Golang
ATOMIC Stealer
ATOMIC Stealer
ATOMIC Stealer, also known as AMOS (Atomic macOS Stealer), targets Mac systems to steal credentials, cryptocurrency wallets, and other sensitive data. It is actively sold on Telegram forums
Known Variants
Known Variants
No widely reported variants but frequently updated for new macOS versions.
No widely reported variants but frequently updated for new macOS versions.
Mitigation Strategies
Mitigation Strategies
Deploy macOS-specific endpoint security, educate users on phishing risks, and monitor for unauthorized data exfiltration.
Targeted Industries or Sectors
Targeted Industries or Sectors
Typically targets macOS users in tech, design, and cryptocurrency spaces.
Typically targets macOS users in tech, design, and cryptocurrency spaces.
Associated Threat Actors
Associated Threat Actors
Linked to small-scale cybercriminal groups focusing on macOS environments.
Linked to small-scale cybercriminal groups focusing on macOS environments.
References
Threat Hunting Platform - Hunt.io
Products
Hunt Intelligence, Inc.
Threat Hunting Platform - Hunt.io
Products
Hunt Intelligence, Inc.
Threat Hunting Platform - Hunt.io
Products
Hunt Intelligence, Inc.