Sunday, September 6, 2026

Atomic macOS Stealer Upgraded with Remote Access Backdoor

The Atomic macOS Stealer (AMOS), a notorious infostealer malware targeting Apple’s macOS ecosystem, has undergone a significant upgrade by incorporating a sophisticated backdoor mechanism that facilitates persistent access and remote command execution on infected systems.

This enhancement, detailed in a recent report by Moonlock Lab, a cybersecurity arm of MacPaw, transforms AMOS from a mere data exfiltration tool into a full-fledged remote access trojan (RAT).

Previously focused on harvesting sensitive information such as cryptocurrency wallet credentials, browser autofill data, and keychain passwords, AMOS now ensures attackers can maintain long-term control, surviving system reboots and enabling the deployment of additional payloads.

This evolution aligns AMOS with advanced persistent threat (APT) tactics, reminiscent of North Korean campaigns that blend stealers with backdoors for rapid exfiltration and surveillance.

Evolution into a Persistent Threat

However, AMOS’s Russia-affiliated developers appear to prioritize sustained persistence, potentially for keylogging, network lateral movement, and ongoing espionage.

Distributed as a malware-as-a-service (MaaS) offering, AMOS has already compromised systems across more than 120 countries, with heightened activity in the United States, United Kingdom, France, Italy, and Canada.

Analysts at PolySwarm classify it as an evolving threat, underscoring the need for robust endpoint detection and response (EDR) solutions to counter its growing sophistication.

At its core, the AMOS backdoor leverages macOS-specific features for stealth and persistence.

Upon infection, the malware deploys a hidden binary named .helper in the user’s home directory, accompanied by a wrapper script called .agent that orchestrates its continuous execution.

Technical Implementation

To achieve boot-time persistence, AMOS installs a LaunchDaemon plist file labeled com.finder.helper via AppleScript, which executes with elevated privileges obtained through stolen user credentials.

This setup allows the backdoor to poll command-and-control (C2) servers via HTTP POST requests every 60 seconds, fetching tasks for remote command execution, file manipulation, or further malware deployment.

Evasion techniques are integral: AMOS employs string obfuscation to hinder static analysis and uses the system_profiler command to detect sandboxed or virtual machine environments, aborting operations if such conditions are identified to avoid detection during reverse engineering.

Distribution primarily occurs through two vectors: spear-phishing campaigns and websites hosting cracked or counterfeit software, often targeting cryptocurrency enthusiasts and freelancers like digital artists.

According to the report, Phishing lures mimic legitimate job interviews, prompting victims to install trojanized DMG files that request system passwords under the guise of enabling screen-sharing tools.

Once executed, AMOS not only exfiltrates data like seed phrases and passwords but also embeds the backdoor for prolonged access.

This shift from one-off theft to persistent compromise amplifies risks, enabling attackers to conduct surveillance, deploy ransomware, or pivot to enterprise networks.

As AMOS continues to iterate with rumors of impending keylogging capabilities, macOS users must adopt proactive defenses, including behavior-based monitoring, regular software updates, and caution with unsolicited downloads.

The malware’s global reach and technical refinements position it as a critical threat, demanding heightened vigilance in an ecosystem often perceived as inherently secure.

Indicators of Compromise (IOCs)

SHA-256 HashPolySwarm Scan Link
8d8b40e87d3011de5b33103df2ed4ec81458b2a2f8807fbb7ffdbc351c7c7b5eView Scan
3402883ff6efadf0cc8b7434a0530fb769de5549b0e9510dfdd23bc0689670d6View Scan
f4976d9a90d2f9868fcaade1449ffcf9982ed2285ace90aafa7099ce246fd2ecView Scan
54b9576aad25d54d703adb9a26feaa5d80f44b94731ff8ecff7cf1ebc15cf3ffView Scan
11e55fa23f0303ae949f1f1d7766b79faf0eb77bccb6f976f519a29fe51ce838View Scan
ec11fd865c2f502c47f100131f699a5e0589092e722a0820e96bd698364eefdbView Scan

Find this News Interesting! Follow us on Google News, LinkedIn, & X to Get Instant Updates!

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security

Chainguard has surpassed 1 billion container build manifests, doubling...

Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe

Russian state-sponsored threat actor BlueDelta, also tracked as APT28,...

New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption

Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS)...

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged...

Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours

A threat actor used frontier artificial-intelligence models and attack-specific...

CARS24 Data Breach Exposes 3,100 Customer Records, Leads Allegedly Sold for ₹1,000 Each

Used-car platform CARS24 has alleged that confidential information belonging...

Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors

The financially motivated threat actor Toy Ghouls has expanded...

Related Articles

Recent News