Atomic macOS Stealer Malware Can Steal Keychain Info, Files, Browser Wallets and More

While Apple's Macs are less targeted by malware than Windows PCs, concerning Mac malware does pop up regularly. This week, there's new Mac malware out in the wild that Mac users should be aware of.

macos atomic malware demo
Called Atomic macOS Stealer (AMOS), the malware was found on Telegram by Cyble Research. A Telegram user was selling access to the malware, which is designed to steal sensitive information like usernames and passwords.

Whoever designed the Atomic macOS Stealer is working behind the scenes to improve it and add new functionality to make it more effective. In its current incarnation, AMOS is able to access keychain passwords, system information, files from the desktop and documents folder, and the password of the Mac.

It is able to infiltrate browser apps like Chrome and Firefox, extracting autofill information, passwords, cookies, wallets, and credit card information. Cryptowallets like Electrum, Binance, and Atomic are specific targets.

macos atomic malware
AMOS can be purchased with a web panel that makes it easy to manage malware targets, along with tools for brute-forcing private keys. The malware and accompanying services to make it easier to use against victims can be purchased on Telegram for $1,000 per month.

A .dmg file is used to get the malware on a victim's machine, and once installed, it immediately begins accessing sensitive information and sending it to a remote server. A fake system prompt is presented to get access to the system password, and it asks for access to files in the documents and desktop folders.

Because this requires a user to click on a .dmg file to install, Mac users can avoid the malware by not installing any kind of untrusted software from an unverified source. Cyble Research recommends installing software from the Mac App Store, using strong passwords and multi-factor authentication, and using biometric authentication where possible.

Users should also avoid opening links in emails, using caution whenever an app asks for permissions, and keeping devices, operating systems, and apps up to date.

Top Rated Comments

matt_and_187_like_this Avatar
11 months ago
Even malware is on a subscription model these days
Score: 112 Votes (Like | Disagree)
AtomicDusk Avatar
11 months ago
hey y’all, I just want to hijack this thread and say that I can’t wait for sideloading on iOS because you can put whatever you want on your Mac.
Score: 40 Votes (Like | Disagree)
sw1tcher Avatar
11 months ago

Sounds like a great reason to only install from the App Store.

It's Apple behind this to prove why it's better to keep the App Store only for iOS and then do the same for the Mac!
Except Apple allows crapware onto their Mac App store too

not to mention all the junk on their iOS App store ('')
Score: 31 Votes (Like | Disagree)
LV426 Avatar
11 months ago
Next time macOS goes a bit loopy (literally) after an update and keeps asking you to re-enter your Apple ID password, you'd be justified in worrying that something like this is having a go at you.
Score: 20 Votes (Like | Disagree)
Rychiar Avatar
11 months ago

I only rely on Apple’s own Apple App Store on Mac. ?
I can’t think of anything i’ve ever gotten from the App Store. Even adobe isn’t on the App Store. Nor are things like VLC, superduper, emulators, bit torrent clients. Pretty much anything that makes a Mac Better than an iPad
Score: 18 Votes (Like | Disagree)
natnorth Avatar
11 months ago
Looking at that browser list... you can see why Chrome and pretty much all "competing" browsers based on chrome isn't great for web competition. Firefox is the only one of two on there that doesn't hand over passwords
Score: 17 Votes (Like | Disagree)

Popular Stories

Apple Logo Spotlight

Source: Apple to Announce New Products This Week

Sunday March 3, 2024 11:38 am PST by
Apple plans to announce new products with press releases on its website this week, a proven source familiar with the matter told MacRumors. While the products that Apple plans to announce have not been disclosed, there are rumors about new iPads, Macs, and accessories. It is unclear exactly what will be announced this week. Bloomberg's Mark Gurman today reiterated that Apple is planning new...
Apple Maps vs Google Maps Feature

Apple Maps vs. Google Maps: Which Is Better?

Friday March 1, 2024 7:10 am PST by
Apple Maps has been providing navigational guidance to Apple users for almost 13 and a half years now, and much has changed about the app in that time. However, according to data from Canalys, the overwhelming majority of iPhones in the U.S. still have Google Maps downloaded as an alternative to Apple Maps, which comes preinstalled on all iPhones. We want to hear from MacRumors readers. Which do...
apple tv plus banner

Apple TV+ Gains Over 50 Movies for a Limited Time

Friday March 1, 2024 6:29 am PST by
Apple TV+ today gained over 50 movies, adding to its back catalog of content for a limited time. The collection includes a large number of popular and classic titles. Subscribers can access the movies in a "Great Movies on Apple TV+" section in the Apple TV app. Some titles are also available in 3D. Movies in the collection include: 21 Jump Street 300 American Sniper Argo ...
iPad Air 12

Gurman: No Apple Event Planned for Upcoming iPads and Macs

Sunday March 3, 2024 5:09 am PST by
Apple does not plan to hold a traditional event to unveil new iPads and Macs, according to Bloomberg's Mark Gurman. Instead, he said Apple plans to announce the products on its website with a "series of online videos and marketing campaigns." If this plan is accurate, we can expect the new products to be announced with press releases on the Apple Newsroom website. Gurman expects Apple to...
airpods pro 2 pink

Apple Releases New Beta Firmware for AirPods Pro 2

Thursday February 29, 2024 11:41 am PST by
Apple today introduced a new beta firmware update for the AirPods Pro 2, both the USB-C and Lightning versions. The new firmware is version 6E188, up from the prior 6B34 firmware released in December. Apple does not often provide details or notes on what features might be included in the refreshed firmware, so it is unclear what's new. Note that this software is limited to developers at the...