Atomic MacOS (AMOS) Stealer Infects macOS Users – Credential Harvesting Campaign
What Happened — A new macOS‑focused credential stealer, dubbed Atomic MacOS (AMOS), was observed in the wild delivering stolen browser passwords, cryptocurrency wallets, and system information to a remote C2. The campaign leverages malicious installers and compromised software updates to gain persistence on victim machines.
Why It Matters for Compliance & Audit Readiness
- Credential theft is a classic violation of SOC 2 CC6 (Logical Access) and CC7 (System Operations) – controls that must be continuously monitored and evidenced.
- Detecting and evidencing the presence of unauthorized macOS agents is essential for a defensible audit trail and for demonstrating due‑diligence in access‑control governance.
- Verisq’s Security Awareness Training capability helps embed the “don’t run unknown installers” habit, while providing audit‑ready training records that map to SOC 2 requirements.
Who Is Affected – Primarily technology‑focused enterprises, SaaS providers, and any organization with macOS workstations (tech, media, design, finance, and education sectors).
Recommended Actions
- Validate that macOS endpoint protection is deployed and that its logs are collected for continuous monitoring.
- Enforce MFA on all privileged accounts and require strong password policies.
- Run a focused security‑awareness module on macOS‑specific phishing and malicious‑installer tactics; retain completion evidence for audit.
- Update your SOC 2 access‑control inventory to include macOS devices and map the new control evidence to CC6/CC7.
Source: SANS Internet Storm Center – Atomic MacOS (AMOS) stealer infection
Technical Notes – AMOS is delivered via a signed‑but‑compromised installer, installs a launch daemon for persistence, and exfiltrates data over HTTPS to a hard‑coded C2 domain. No public CVE is associated; the threat relies on user execution and lack of macOS‑specific endpoint controls.