Friday, September 11, 2026

Atomic macOS Info-Stealer Updated with New Backdoor for Persistent Access

The Atomic macOS Stealer (AMOS), a notorious piece of info-stealing malware targeting Apple users, has undergone a significant update, introducing an embedded backdoor for the first time.

This development, reported by Moonlock a cybersecurity division of MacPaw marks a critical escalation in the malware’s capabilities, allowing attackers to maintain persistent access to compromised macOS systems.

A Dangerous Evolution in macOS Malware

Unlike its previous focus on data exfiltration from cryptocurrency-related browser extensions and wallets, AMOS now enables remote command execution, full user-level access, and system persistence even after reboots.

This upgrade positions AMOS as one of the most dangerous threats to macOS users, with campaigns already spanning over 120 countries, including the United States, France, Italy, the United Kingdom, and Canada.

Atomic macOS
macOS is a trademark of Apple Inc.

The addition of a backdoor transforms AMOS from a one-time data theft tool into a platform for long-term surveillance and exploitation.

The malware is primarily distributed through websites hosting cracked or fake software and sophisticated spear-phishing campaigns targeting high-value individuals, such as cryptocurrency holders.

From Data Theft to Full System Compromise

The infection process often mimics legitimate processes, such as job interviews, tricking victims into entering system passwords.

Once executed, AMOS deploys a trojanized DMG file that bypasses macOS Gatekeeper protections using a Mach-O binary, bash scripts, and AppleScript.

Atomic macOS
AppleScript 

Beyond the initial data theft, the backdoor is established via persistence mechanisms like LaunchDaemon PLIST files, ensuring the malware survives system reboots.

The backdoor, hidden as “.helper” and supported by a “.agent” script, communicates with command-and-control (C2) servers to fetch tasks, execute shell commands, or self-delete, mirroring tactics seen in North Korean attack strategies.

Data exfiltration occurs over HTTP POST requests to specific IP addresses, while new features like keylogging are reportedly in testing, further expanding the threat’s potential.

This update, believed to be only the second instance of a globally scaled backdoor targeting macOS after North Korean campaigns, signifies a shift in intent, whether by the original Russia-affiliated AMOS developers or other actors modifying the code.

The active C2 infrastructure, along with URLs fetching malicious payloads (e.g., from isnimitz[.]com), indicates the campaign is in full swing.

Moonlock warns that the malware-as-a-service (MaaS) model could lead to more variants, enhancing evasion techniques and exploitation opportunities.

For Mac users, the risk now extends beyond stolen credentials to complete system compromise, necessitating immediate awareness and robust defenses like anti-malware tools to detect and block AMOS before it embeds itself.

Indicators of Compromise (IOCs)

TypeValue
IP Address45.94.47.158
IP Address45.94.47.157
IP Address45.94.47.146
IP Address45.94.47.147
IP Address45.94.47.145
URLhttp://45.94.47.147/contact
URLhttp://45.94.47.145/contact
URLhttp://45.94.47.146/contact
URLhttp://45.94.47.147/api/tasks/
SHA2568d8b40e87d3011de5b33103df2ed4ec81458b2a2f8807fbb7ffdbc351c7c7b5e
SHA2563402883ff6efadf0cc8b7434a0530fb769de5549b0e9510dfdd23bc0689670d6

Stay Updated on Daily Cybersecurity News . Follow us on Google News, LinkedIn, and X.

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News