This report details an Atomic macOS (AMOS) Stealer infection campaign observed on October 2, 2026. The attack originates from a malicious advertisement impersonating Anthropic's "Claude Code" developer tool. Victims are lured to a spoofed website that utilizes a "ClickFix" social engineering technique, which tricks users into copying and pasting a malicious command directly into their macOS Terminal to supposedly resolve a software issue.
Once executed, the Terminal script initiates the AMOS Stealer, which prompts the user for administrative credentials and system permissions. This malware is designed to harvest sensitive information, including browser data and crypto wallets, from the infected macOS system. The campaign highlights the increasing sophistication of macOS-targeted malware and the effective use of developer-focused social engineering lures.
Top comments (0)