Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: macOS users
Incident: Deployment of AMOS infostealer via browser fingerprinting and social engineering.
Impact: Theft of browser credentials, authentication stores, cryptocurrency wallets, and sensitive files.
Attacker: Unidentified threat actors
Analysis: The campaign employs server-side validation to distinguish genuine macOS users from automated crawlers or analysts. By analyzing device telemetry and browser behavior, attackers only reveal malicious prompts to high-value targets. Once tricked, users execute obfuscated Terminal commands that deploy the Atomic Stealer (AMOS) infostealer.
Recommendations: Educate users never to paste unknown commands into the macOS Terminal; Implement DNS filtering to block suspicious domains combining ‘file’ with dictionary terms; Monitor for unauthorized shell process activity fetching remote scripts on macOS endpoints
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source
Latest Developments
Update — 2026-08-06 20:58 UTC
A social engineering campaign uses ‘ClickFix’ prompts to deploy a Go-based credential stealer on Mac devices. Loss of cryptocurrency funds and compromise of stored system and browser credentials. The attack employs a fake CAPTCHA prompt to trick users into pasting a malicious string into the macOS Terminal. This triggers a multi-stage download resulting in a Go-based stealer that targets the Apple Keychain and browser password stores. The malware specifically includes functionality to identify and drain cryptocurrency wallet balances.
Corroborating source: huntress.com