HomeSecurityAtomic macOS malware adds backdoor mechanism

Atomic macOS malware adds backdoor mechanism

MacPaw's Moonlock cybersecurity team has uncovered a particularly disturbing development in the macOS malware landscape. Working with independent researcher g0njxa , they have identified a new, advanced version of the notorious Atomic macOS Stealer (AMOS), which incorporates a backdoor mechanism that allows cybercriminals to maintain permanent access to infected systems.

Atomic macOS Amos malware

The addition of this backdoor transforms AMOS from an infostealer into a full-control tool, allowing for remote execution of arbitrary commands, even after system reboots. According to Moonlock, the new variant is capable of installing silently, remaining invisible to the user, and providing attackers with the ability to record keystrokes, inject additional payloads, or even attempt lateral movement within an organization.

See also: North Korean hackers use new macOS malware NimDoor

Global campaigns – focused on crypto

Atomic was first detected in April 2023 and operates on a malware-as-a-service (MaaS). It is offered through Telegram channels for a monthly subscription fee of up to $1,000. Since then, it has been deployed in over 120 countries, with the US, France, Italy, the UK and Canada being the most affected.

Initially distributed via compromised software websites, however, there has recently been a shift towards targeted phishing campaigns – particularly targeting cryptocurrency holders and freelancers through fake job interview invitations.

Technical characteristics of the backdoor

The new version of Atomic includes:

  • An executable binary named .helper, which is installed in the user's home folder as a hidden file.
  • A wrapper script (.agent) that restarts .helper continuously, even after a system reboot.
  • A LaunchDaemon (com.finder.helper), installed via AppleScript, that launches .agent with every macOS startup.

This action is performed with elevated privileges using the user's password, which was stolen during the initial phase of the infection under false pretenses. The malware can then execute commands and change the ownership of the LaunchDaemon PLIST to 'root:wheel' (superuser level on macOS).

See also: BlueNoroff distributes MacOS malware via deepfake videos in Zoom meetings

Additionally, the backdoor applies anti-forensics techniques, such as avoiding sandbox environments and virtual machines via system_profiler, as well as hiding strings to avoid detection by antivirus tools.

Atomic macOS malware adds backdoor mechanism
Atomic macOS malware adds backdoor mechanism

The message to the macOS: you are no longer immune

The case of Atomic Stealer dispels the myth that macOS users are “safer” by default. The speed with which this malware is evolving – and its transition from a simple infostealer to a persistent, backdoor tool full-control – signals a worrying trend.

Attacks are now targeting high-value targets, while utilizing social engineering and technical sophistication that points to organized cybercrime networks.

macOS malware protection

Apple offers some built-in security features, such as Gatekeeper and XProtect to prevent infection.

See also: Banshee: macOS malware abuses XProtect encryption algorithm

But there are some other methods of protection:

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

  • Keep your operating system and software  up to date to patch any known vulnerabilities
  • Be cautious when downloading and opening attachments or files from unknown sources
  • Use a reliable antivirus software, especially if you frequently download files from the Internet.
  • Enable FileVault, which encrypts your data and protects it in case of theft or unauthorized access.
  • Regularly back up your important files to an external hard drive

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS