Amos Stealer Targets macOS Keychain Files and Browser Passwords

2026-06-16T20:51:43Z029c05f1016a5352aa6022d69b38c8c19f17e4ee5b19abd8808b75c1079d56e6
AndroidArgamalCalifornia Water ServiceGitGuardianMagicAdRokarollaapp-storebanking-fraudbrowser-passwordsclipboard-hijackcookiescredential-theftcritical-infrastructurecrypto-targetingdata-breachdeepfakedeveloper-configsendpoint-protectionhandalakeychainlaw-enforcementmacOSmobile-malwaresupply-chaintrojan

What happened

Multiple active threats and incidents reported: Amos Stealer is being distributed via fake macOS downloads to exfiltrate Keychain files, browser passwords, cookies and developer configs; new Android threats include Rokarolla (targets 217 crypto and banking apps, performs clipboard hijacking, call blocking and device takeover) and MagicAd (embedded in 50+ apps on official stores to force background ads); Argamal RAT is being distributed inside working hentai game installers to provide remote access; the Handala group claims a breach of California Water Service and leaked ~5GB of customer and GP

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
029c05f1016a5352aa6022d69b38c8c19f17e4ee5b19abd8808b75c1079d56e6
Enrichment time
2026-06-16T20:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.