Amos Stealer Targets macOS Keychain Files and Browser Passwords
2026-06-16T20:51:43Z•029c05f1016a5352aa6022d69b38c8c19f17e4ee5b19abd8808b75c1079d56e6
AndroidArgamalCalifornia Water ServiceGitGuardianMagicAdRokarollaapp-storebanking-fraudbrowser-passwordsclipboard-hijackcookiescredential-theftcritical-infrastructurecrypto-targetingdata-breachdeepfakedeveloper-configsendpoint-protectionhandalakeychainlaw-enforcementmacOSmobile-malwaresupply-chaintrojan
What happened
Multiple active threats and incidents reported: Amos Stealer is being distributed via fake macOS downloads to exfiltrate Keychain files, browser passwords, cookies and developer configs; new Android threats include Rokarolla (targets 217 crypto and banking apps, performs clipboard hijacking, call blocking and device takeover) and MagicAd (embedded in 50+ apps on official stores to force background ads); Argamal RAT is being distributed inside working hentai game installers to provide remote access; the Handala group claims a breach of California Water Service and leaked ~5GB of customer and GP
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 029c05f1016a5352aa6022d69b38c8c19f17e4ee5b19abd8808b75c1079d56e6
- Enrichment time
- 2026-06-16T20:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.