Friday, September 11, 2026

Malvertising Campaign Spreads AMOS ‘malext’ macOS Infostealer via Fake Text-Sharing Ads

A large-scale malvertising operation targets macOS users with fake Google Ads leading to malicious text-sharing sites. These lures deliver the AMOS infostealer variant, dubbed “malext,” which steals sensitive data such as browser credentials and crypto wallets.

Suspicious password prompts halted the compromise, revealing initial domains like optimize-storage-mac-os[.]medium[.]com, octopox[.]com, and vagturk[.]com.​

Google Ads Library exposed over 34 ads pushing Medium.com lures, with attackers rapidly replacing banned accounts.

Analysis found 53+ compromised ad accounts, including one promoting cruises alongside fake macOS fixes. Similar ads hit Evernote.com, mssg.me, and kimi.com platforms.​

Researchers @itspappy and Gi7w0rm uncovered the attack after a near-miss incident. A user searching for macOS storage fixes clicked a top Google result, landing on a fake Medium post with a malicious shell command.

Cruiseship Ad account pushing MacOS USB upgrade AD (Source : Medium).
Cruiseship Ad account pushing MacOS USB upgrade AD (Source : Medium).

Lures mimic troubleshooting guides for macOS issues or software installs. Pages feature headlines like “This method fixes X,” followed by Terminal commands to copy-paste.

Base64-obfuscated curls chain downloads, stripping quarantine attributes with xattr -c to evade Gatekeeper.​

Some chains prompt for admin passwords via loops, storing them in ~/.pass for later sudo use. This social engineering boosts payload execution without alerts.​

Kill Chain Analysis

Commands download Mach-O binaries supporting x86_64 and ARM. These run VM/sandbox checks via obfuscated AppleScript using system_profiler for QEMU/VMware detection or odd hardware signatures. Patched samples ran in VirusTotal, revealing a 59k+ char osascript payload.​

Deobfuscation shows Caesar cipher strings and randomized vars. The script hides Terminal, collects system info, and exfils via malext[.]com or 38.244.158[.]56.​


lite.evernote.com lure (Source : Medium).
lite.evernote.com lure (Source : Medium).

The “malext” AMOS variant steals broadly. It grabs Apple Notes DB, Safari cookies, Desktop/Documents files (txt/pdf/docx/wallet up to 30MB), OpenVPN profiles, Telegram data, and installed apps list.​

The malware is that the macho file actually contained 2 payload binaries compiled for different CPU Architectures.

Macho file contains payloads for both ARM and x86–64 (Source : Medium).
Macho file contains payloads for both ARM and x86–64 (Source : Medium).

Targets 12+ Chromium browsers (Chrome/Brave/Edge etc.) for cookies/logins/history, Firefox profiles, 266 extensions (crypto/password managers), login keychain, and 16+ wallets (Electrum/Exodus/Ledger etc.). Zips data to /tmp/out.zip and POSTs with token/build ID headers.

Persistence and Backdoor

With stolen password, it trojanizes Ledger/Trezor apps via sudo replacements from malext[.]com/app.zip. Installs LaunchDaemon com.finder.helper.plist running ~/.agent loop to fetch/execute ~/.mainhelper from C2 /zxc/kito, enabling remote control.​

The code sets up several config variables that can enable/disable partial functionalities, like file stealing or Apple Notes stealing.

C2 Config of this AMOS Stealer sample (Source : Medium).
C2 Config of this AMOS Stealer sample (Source : Medium).
FeatureDescriptionTargets
Data TheftBrowsers, wallets, keychain, filesChrome, Electrum, Notes​
EvasionVM check, xattr -c, gzip/Base64Gatekeeper, sandboxes​
PersistenceLaunchDaemon, trojanized apps~/.agent, Ledger​
C2HTTP POST retries, fallback IPmalext[.]com, 199.217.98.33​

Traits match AMOS over Odyssey: com.finder.helper.plist, BuildID header, /zxc paths despite cl/cn:0 headers. Active since late 2025, it scales via cheap throwaway accounts, possibly trafficker-run.​

Users should avoid untrusted Terminal commands, verify ads, and scan with antivirus. Rotate creds if exposed.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News