unit42.paloaltonetworks.com 16 Sept 2026, 10:00 UTC

Fake macOS Toolkit Site Installs AMOS Stealer and Targets Wallets

Fake macOS Toolkit Site Installs AMOS Stealer and Targets Wallets
CyberSIXT Evidence Panel Source marked as original reporting

PALO Alto Networks’ Unit 42 has analysed a laboratory infection involving Atomic macOS (AMOS) stealer, based on activity observed on 5 August 2026. The malware was distributed through a website, getmacouscloud[.]com, which falsely offered instructions for installing a “macOS toolkit”. Following those instructions caused text to be pasted into a macOS Terminal window. The command downloaded a Z-shell script containing a Base64-encoded, GZIP-compressed payload, which retrieved and ran a Mach-O installer for AMOS.

The installer created files designed to maintain persistence in hidden directories under the user’s Library/Application Support folder, including binaries named AccountsHelper and mdworker_shared. The infection prompted for an administrator password and requested Terminal permissions to control Finder and Notes, and to access the user’s Desktop and Documents folders. In Unit 42’s clean test system, AMOS collected data in /tmp and compressed it into out.zip.

The archive included material associated with Binance and TonKeeper wallets, AWS, Docker, FileZilla and gcloud, zsh history, Telegram data, and the username. The researchers said this content indicated the applications and data types the stealer searched for, rather than confirming those applications were installed.

Post-infection traffic mainly comprised HTTP POST requests to the C2 server 161.35.146[.]120, using stages referring to messengers, credentials, browsers, wallets and local data. A comparable infection on 31 July used a different C2 address, 188.166.78[.]138. Unit 42 said AMOS domains, IP addresses, filenames, hashes and paths change frequently, so the published indicators are only a snapshot.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline