Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)
2026-08-03T01:23:40Z•414e12e065a3bbf301244bdc559e3d3a573011ae37d7f755e2685a9b4c2285ec
AI service impersonationAMOSApple security updatesAtomic StealerAutoITSSH botcryptomininghardware reconnaissanceinfostealermacOSmalwarephishingprocess injectionthreat intelligence
What happened
SANS Internet Storm Center entries covering macOS Atomic Stealer (AMOS) infections, phishing campaigns impersonating AI service providers, SSH bot reconnaissance preceding cryptocurrency miner deployment, AutoIT-based payload injection, and Apple security updates. The collection is threat-intelligence reporting rather than a single confirmed vulnerability, with multiple malware delivery and execution themes.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 414e12e065a3bbf301244bdc559e3d3a573011ae37d7f755e2685a9b4c2285ec
- Enrichment time
- 2026-08-03T01:23:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.