← Back to Feed

Atomic macOS (AMOS) Stealer Activity

September 16, 2026 · Unit 42 · Severity: HIGH

Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42.

Key Takeaways

  • Atomic macOS Stealer uses deceptive setup guides and fake software update prompts to trick Mac users into installing credential-stealing malware on their devices.
  • The stealer targets browser passwords, cryptocurrency wallets, keychain data, and sensitive files, making it one of the most comprehensive macOS threats currently active.
  • Users should verify software sources carefully and avoid running unsigned installer packages to protect against AMOS and similar macOS malware families.
☕ Buy a Coffee