MacPaw's Moonlock cybersecurity team has uncovered a particularly disturbing development in the macOS malware landscape. Working with independent researcher g0njxa , they have identified a new, advanced version of the notorious Atomic macOS Stealer (AMOS), which incorporates a backdoor mechanism that allows cybercriminals to maintain permanent access to infected systems.

The addition of this backdoor transforms AMOS from an infostealer into a full-control tool, allowing for remote execution of arbitrary commands, even after system reboots. According to Moonlock, the new variant is capable of installing silently, remaining invisible to the user, and providing attackers with the ability to record keystrokes, inject additional payloads, or even attempt lateral movement within an organization.
See also: North Korean hackers use new macOS malware NimDoor
Global campaigns – focused on crypto
Atomic was first detected in April 2023 and operates on a malware-as-a-service (MaaS). It is offered through Telegram channels for a monthly subscription fee of up to $1,000. Since then, it has been deployed in over 120 countries, with the US, France, Italy, the UK and Canada being the most affected.
Initially distributed via compromised software websites, however, there has recently been a shift towards targeted phishing campaigns – particularly targeting cryptocurrency holders and freelancers through fake job interview invitations.
Technical characteristics of the backdoor
The new version of Atomic includes:
- An executable binary named .helper, which is installed in the user's home folder as a hidden file.
- A wrapper script (.agent) that restarts .helper continuously, even after a system reboot.
- A LaunchDaemon (com.finder.helper), installed via AppleScript, that launches .agent with every macOS startup.
This action is performed with elevated privileges using the user's password, which was stolen during the initial phase of the infection under false pretenses. The malware can then execute commands and change the ownership of the LaunchDaemon PLIST to 'root:wheel' (superuser level on macOS).
See also: BlueNoroff distributes MacOS malware via deepfake videos in Zoom meetings
Additionally, the backdoor applies anti-forensics techniques, such as avoiding sandbox environments and virtual machines via system_profiler, as well as hiding strings to avoid detection by antivirus tools.

The message to the macOS: you are no longer immune
The case of Atomic Stealer dispels the myth that macOS users are “safer” by default. The speed with which this malware is evolving – and its transition from a simple infostealer to a persistent, backdoor tool full-control – signals a worrying trend.
Attacks are now targeting high-value targets, while utilizing social engineering and technical sophistication that points to organized cybercrime networks.
macOS malware protection
Apple offers some built-in security features, such as Gatekeeper and XProtect to prevent infection.
See also: Banshee: macOS malware abuses XProtect encryption algorithm
But there are some other methods of protection:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- Keep your operating system and software up to date to patch any known vulnerabilities
- Be cautious when downloading and opening attachments or files from unknown sources
- Use a reliable antivirus software, especially if you frequently download files from the Internet.
- Enable FileVault, which encrypts your data and protects it in case of theft or unauthorized access.
- Regularly back up your important files to an external hard drive
Source: www.bleepingcomputer.com
