Mac users once believed their devices were safe from malware. Now, cybercriminals use trusted platforms like ChatGPT and Google Ads to spread the AMOS infostealer, targeting sensitive data on macOS.
This Atomic macOS Stealer (AMOS) grabs browser passwords, cookies, crypto wallets, and Keychain info, then sends it to attackers.
Attackers craft fake shared chats on ChatGPT or Grok with step-by-step guides. These chats trick users into pasting malicious Terminal commands, often disguised as fixes for disk space or browser installs like “ChatGPT Atlas.”
They promote these chats via paid Google Ads, making sponsored links appear at the top of searches on chatgpt.com domains.
Underground Evolution
Cybercriminals run a booming market for macOS stealers on forums like BDFClub.
User Valhall88 posted on January 31, 2026, seeking partners to help develop a stealer targeting 103 Chrome crypto extensions, including Ledger, Trezor, Exodus, and Atomic. They offer a 50/50 split on crypto theft, letting partners keep other data like passwords.
AMOS evolved from basic Terminal tricks to advanced methods. It uses ClickFix schemes, in which users run scripts that download and execute malware after entering their password. The stealer also installs a backdoor for remote control and auto-starts on reboot.
Tools like MacSync bypass Gatekeeper with stolen Apple developer signatures, such as Team ID GNJLS3UYZ4.
Jamf found a notarized Swift app in a DMG file that drops the stealer after passing checks. Apple revoked the cert after reports, but attackers steal or buy credentials to repeat this.
Groups like UNC5142 compromised 14,000 WordPress sites since 2023. They use EtherHiding on the BNB Smart Chain for command-and-control, hiding payloads within blockchain contracts that blend with legitimate Web3 traffic.
Why Macs and Crypto?
Crypto users favor Macs, storing large wallet values like seed phrases that can’t be recovered once stolen. AMOS prioritizes wallets (Electrum, MetaMask, Exodus), validates Trezor recovery phrases to avoid alerts, and lets Exodus work normally after theft.
According to Flare, it steals Chrome, Safari, and Firefox passwords, as well as Keychain passwords, and files like .wallet or .key. Data packs into ZIPs and exfils to C2 servers like meshsorterio.com.
Watch for Terminal commands from ads, for unsigned apps asking for passwords, or for blockchain links from non-crypto apps. Use antivirus software, avoid pasting unknown code, and check suspicious instructions with AI before running.
This mature industry operates like legit software, with panels and roadmaps. Macs need macOS-specific defenses now.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.