Monday, September 7, 2026

Over 2,800 Hacked Websites Targeting MacOS Users with AMOS Stealer Malware

Cybersecurity researcher has uncovered a massive malware campaign targeting MacOS users through approximately 2,800 compromised websites.

The operation, dubbed “MacReaper,” uses sophisticated social engineering and blockchain technology to deliver the Atomic Stealer (AMOS) malware, capable of stealing passwords, cryptocurrency wallets, and sensitive information from Apple devices.

Initially discovered on May 4, 2025, through a compromised Brazilian news site, this campaign represents one of the largest coordinated attacks against the MacOS ecosystem.

The campaign employs a deceptive technique known as “ClickFix” or “ClearFix” that displays fake Google reCAPTCHA verification interfaces exclusively to MacOS users.

When visitors click “I’m not a robot,” they’re presented with a verification dialog containing MacOS-specific instructions to open Terminal using familiar Apple keyboard shortcuts (⌘ + Space to open Spotlight, followed by ⌘ + V to paste).

The fake interface automatically copies malicious commands to the user’s clipboard, which when executed, download and run the AMOS malware.

“The attack is meticulously designed to target MacOS users, using a combination of client-side and server-side mechanisms to ensure the ClickFix interface is displayed only on MacOS devices,” notes the researcher who identified the threat.

The malware itself, available on underground forums since April 2023 as a Malware-as-a-Service offering for $1,000-$3,000 monthly, uses a signed Mach-O binary that bypasses MacOS Gatekeeper security protections.

Blockchain-Based Infrastructure

What makes this campaign particularly sophisticated is its use of “EtherHiding,” a technique where malicious commands are embedded in Binance Smart Contract blockchain transactions to evade detection and resist takedowns.

This approach provides attackers with a resilient command and control infrastructure that traditional security measures struggle to block.

The investigation began with agencia2.jornalfloripa.com.br and expanded as the researcher uncovered thousands of other sites using identical attack methodologies.

The delivery system leverages obfuscated JavaScript, multiple full-screen overlays, and blockchain-based command retrieval to ensure the attack succeeds while remaining difficult to detect or disrupt.

Once installed, AMOS targets valuable user data, including Keychain passwords, browser data, cryptocurrency wallets, system information via system_profiler, and files from Desktop and Documents folders.

The stealer specifically targets over 50 different cryptocurrency wallets and extensions, representing a significant financial threat to users.

Protect Your Mac from This Threat

According to the Report, Security experts recommend several measures to protect against this expanding threat:

  1. Never execute Terminal commands prompted by websites, particularly those presented through CAPTCHA or verification interfaces.
  2. Monitor network traffic for suspicious connections to domains like technavix.cloud or salorttactical.top associated with this campaign.
  3. Use endpoint detection tools capable of identifying unusual Keychain access or system_profiler execution.
  4. Implement content security policies to block unauthorized scripts on websites you manage.
  5. Keep your macOS and security software updated with the latest patches.

If you suspect your device has been compromised, experts recommend quarantining the system, scanning with macOS-specific antivirus tools, and resetting passwords for Keychain, browsers, and cryptocurrency wallets.

The discovery underscores the growing sophistication of threats targeting Apple’s ecosystem.

With approximately 2,800 compromised websites identified so far, ranging from news outlets to personal blogs, the scale indicates a well-resourced threat actor specifically targeting the growing macOS user base worldwide.

Setting Up SOC Team? – Download Free Ultimate SIEM Pricing Guide (PDF) For Your SOC Team -> Free Download

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

CrowdStrike Launches SafeMind Agentic AI Cybersecurity System Built With NVIDIA Nemotron

CrowdStrike has launched SafeMind, an AI-driven cybersecurity system developed...

Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security

Chainguard has surpassed 1 billion container build manifests, doubling...

Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe

Russian state-sponsored threat actor BlueDelta, also tracked as APT28,...

New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption

Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS)...

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged...

Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours

A threat actor used frontier artificial-intelligence models and attack-specific...

CARS24 Data Breach Exposes 3,100 Customer Records, Leads Allegedly Sold for ₹1,000 Each

Used-car platform CARS24 has alleged that confidential information belonging...

Related Articles

Recent News