Netskope Threat Labs

Amos

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Amos is macOS malware, known as Atomic Stealer, that steals credentials, browser data, and cryptocurrency wallet information from infected machines. Criminal groups sell it as a subscription service, and they typically deliver it through fake advertisements, cloned websites, and social engineering lures that persuade users to open unsigned disk images. Once a victim enters the system password, the malware can read browser secrets, keychain data, and crypto wallet files.

First seen
May 2023
Last seen
October 2026
AMOSStealerAmosStealerAtomicSteal
Alert Name
Gen:Variant.MAC.Amos.10
Gen:Variant.MAC.Amos.12
Gen:Variant.MAC.Amos.2
Gen:Variant.MAC.Amos.4
Gen:Variant.MAC.Amos.8
Gen:Variant.MAC.Amos.9
Generic.SH.Amos.A.0270F070
Generic.SH.Amos.A.032C6A60
Generic.SH.Amos.A.046695E3
Generic.SH.Amos.A.05B1BB07