HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Atomic MacOS (AMOS) Stealer Infects macOS Users – Credential Harvesting Campaign

A new macOS‑focused stealer (Atomic MacOS/AMOS) is delivering stolen passwords and wallet keys to a remote C2. The campaign highlights gaps in endpoint controls and user awareness, underscoring the need for SOC 2‑aligned access‑control monitoring and training.

LiveThreat™ Intelligence · 📅 August 02, 2026· 📰 isc.sans.edu
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
isc.sans.edu

Atomic MacOS (AMOS) Stealer Infects macOS Users – Credential Harvesting Campaign

What Happened — A new macOS‑focused credential stealer, dubbed Atomic MacOS (AMOS), was observed in the wild delivering stolen browser passwords, cryptocurrency wallets, and system information to a remote C2. The campaign leverages malicious installers and compromised software updates to gain persistence on victim machines.

Why It Matters for Compliance & Audit Readiness

- Credential theft is a classic violation of SOC 2 CC6 (Logical Access) and CC7 (System Operations) – controls that must be continuously monitored and evidenced.

- Detecting and evidencing the presence of unauthorized macOS agents is essential for a defensible audit trail and for demonstrating due‑diligence in access‑control governance.

- Verisq’s Security Awareness Training capability helps embed the “don’t run unknown installers” habit, while providing audit‑ready training records that map to SOC 2 requirements.

Who Is Affected – Primarily technology‑focused enterprises, SaaS providers, and any organization with macOS workstations (tech, media, design, finance, and education sectors).

Recommended Actions

- Validate that macOS endpoint protection is deployed and that its logs are collected for continuous monitoring.

- Enforce MFA on all privileged accounts and require strong password policies.

- Run a focused security‑awareness module on macOS‑specific phishing and malicious‑installer tactics; retain completion evidence for audit.

- Update your SOC 2 access‑control inventory to include macOS devices and map the new control evidence to CC6/CC7.

Source: SANS Internet Storm Center – Atomic MacOS (AMOS) stealer infection

Technical Notes – AMOS is delivered via a signed‑but‑compromised installer, installs a launch daemon for persistence, and exfiltrates data over HTTPS to a hard‑coded C2 domain. No public CVE is associated; the threat relies on user execution and lack of macOS‑specific endpoint controls.

📰 Original Source
https://isc.sans.edu/diary/rss/33208

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →