Skip to main content

AMOS Stealer: Evolving macOS Info-Stealer Tactics & Mitigation

4 min read Runtime Rebel Intel
Primary source: unit42.paloaltonetworks.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • AMOS stealer actively compromises macOS systems, exfiltrating credentials, system data, and crypto wallet information.
  • macOS users who fall for social engineering tactics and execute malicious commands are at risk.
  • Educate users against untrusted Terminal commands and implement robust endpoint detection and response (EDR).

Advertisement

Understanding Atomic macOS Stealer (AMOS) Evolution

The Atomic macOS Stealer, commonly known as AMOS stealer, represents a significant and growing threat targeting macOS systems. This sophisticated information stealer actively exfiltrates sensitive data, including login credentials, system information, and cryptocurrency wallet details. Recent analysis by Unit 42 details the infection chain and evolving tactics of this malware, providing critical insights for cybersecurity professionals. AMOS stealer is notable for its dynamic infrastructure, where indicators such as domains, IP addresses, and file paths change frequently, making detection and tracking challenging.

AMOS Stealer Distribution and Initial Access

AMOS stealer propagates through various deceptive methods, often leveraging user interaction to initiate the infection. A primary vector involves malicious websites masquerading as legitimate software download portals or offering cracked versions of popular macOS applications. For instance, the source details a lab infection originating from a page on getmacouscloud[.]com that claimed to offer a “macOS toolkit.”

Attackers guide users to copy and paste a command into their macOS Terminal, a technique the source describes as similar to “ClickFix” campaigns, though it clarifies it’s not strictly the same. This command typically retrieves a Z-shell (Zsh) script from a remote server (e.g., hxxps[:]//ferncore13[.]com/curl/...). This initial script then deploys a GZIP-compressed payload containing a follow-up Zsh script designed to retrieve and execute the AMOS stealer Mach-O binary. During this process, the macOS host may prompt the user for their password if they have administrative privileges, and subsequently request various permissions. This requirement for user interaction underscores the importance of user education in preventing initial compromise.

Infection Chain and Persistence Mechanisms

Once executed, the AMOS stealer Mach-O binary typically establishes persistence on the infected system. The analysis observed the installer saving itself as /tmp/helper, alongside a plist file /tmp/starter. This plist file hints at the creation of a shell script named .service and an AMOS stealer Mach-O file called AccountsHelper within the /Library/Application Support/.com.apple.accountsd/ directory.

Furthermore, additional persistence mechanisms were identified in the /Library/Application Support/.com.apple.metadata.mds/ directory, involving a shell script .mdworker and another AMOS stealer Mach-O file mdworker_shared. These locations and naming conventions attempt to mimic legitimate macOS system processes, helping the malware evade detection. Understanding AMOS stealer persistence mechanisms is crucial for effective endpoint security and incident response.

The malware systematically searches for sensitive data across the compromised macOS host. This includes system information, login credentials from web browsers, and data from cryptocurrency wallets. Collected data is temporarily staged and compressed into an out.zip file in the /tmp directory before being exfiltrated. Post-infection network traffic primarily consists of HTTP POST requests to command and control (C2) servers, with observed C2 IPs like 161.35.146[.]120 and 188.166.78[.]138. The specific URLs for these requests often indicate the type of data being exfiltrated.

Recommendations for Mitigating macOS Info Stealer Threats

Given the evolving nature of AMOS stealer, a multi-layered defense strategy is essential for protecting macOS environments. To detect AMOS stealer macOS activity and prevent infections, security teams should prioritize the following actions:

  • User Education: Emphasize the dangers of copying and pasting commands from untrusted websites into the Terminal. Users should be wary of prompts requesting their password for seemingly benign operations.
  • Least Privilege: Implement the principle of least privilege for user accounts. Regular users should not have administrative access, limiting the impact of successful malware execution.
  • Endpoint Detection and Response (EDR): Deploy EDR solutions capable of monitoring macOS systems for suspicious process activity, file modifications in critical system directories (/Library/Application Support/), and unusual network connections to known C2 infrastructure.
  • Network Monitoring: Monitor outbound network traffic for connections to suspicious IP addresses and domains, particularly HTTP POST requests indicating data exfiltration. The dynamic nature of AMOS C2 infrastructure necessitates behavioral analysis rather than relying solely on static indicators.
  • Regular Software Updates: Ensure all macOS systems and applications are kept up-to-date with the latest security patches to minimize the risk of exploitation by other potential vulnerabilities.
  • Browser and Wallet Security: Advise users to employ strong, unique passwords for all online accounts, utilize password managers, and enable multi-factor authentication (MFA) wherever possible. For cryptocurrency users, consider hardware wallets for enhanced security.

By adopting these proactive measures, organizations can significantly enhance their resilience against sophisticated macOS information stealers like AMOS.

Related: ClickLock macOS Stealer: How Attackers Coerce Victims via App Kill Loops, ClickLock macOS Malware: Password Theft via Forced Login Prompt

Advertisement

Advertisement