Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)

2026-08-03T01:23:40Z414e12e065a3bbf301244bdc559e3d3a573011ae37d7f755e2685a9b4c2285ec
AI service impersonationAMOSApple security updatesAtomic StealerAutoITSSH botcryptomininghardware reconnaissanceinfostealermacOSmalwarephishingprocess injectionthreat intelligence

What happened

SANS Internet Storm Center entries covering macOS Atomic Stealer (AMOS) infections, phishing campaigns impersonating AI service providers, SSH bot reconnaissance preceding cryptocurrency miner deployment, AutoIT-based payload injection, and Apple security updates. The collection is threat-intelligence reporting rather than a single confirmed vulnerability, with multiple malware delivery and execution themes.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
414e12e065a3bbf301244bdc559e3d3a573011ae37d7f755e2685a9b4c2285ec
Enrichment time
2026-08-03T01:23:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.