A sophisticated malware targeting macOSis exploiting users' widespread desire for free (cracked) software to distribute the infamous Atomic Stealer (AMOS).

This information-stealing malware disguises itself as cracked versions of popular applications, tricking unsuspecting users into thinkingthey are simply downloading free software alternatives.
The campaign represents a significant shift in the cybersecurity landscape, challenging the long-held perception that macOS devices are inherently more secure than their Windows counterparts. As Apple devices gain popularity among professionals and high-value targets, cybercriminals have adapted their tactics to exploit this growing market.
See also: US: Malware campaign targets trade talks with China
Attackers use multiple distribution methods and constantly change their infrastructure to evade detection. The malware’s reach extends far beyond simple data theft, targeting sensitive information such as browser credentials, crypto wallets, Telegram chats, VPN settings, keychain data, Apple notes, and various files.
This comprehensive approach to data collection makes Atomic Stealer particularly dangerous for both individual users and corporate environments . Compromised credentials can lead to broader breaches of the organization. Trend Micro researchers detected this campaign through Managed Detection and Response services, noting the malware’s ability to bypass traditional security measures through social engineering (rather than technical exploits).
Atomic Stealer Distribution
The analysis revealed that the attackers primarily distribute Atomic Stealer through websites such as haxmac.cc, which hosts numerous cracked macOS applications and acts as the initial infection point. The distribution strategy involves redirecting users through a complex network of rotating domains.
See also: Abuse of iCloud Calendar to send phishing emails

These redirectors ultimately lead victims to pages hosted on domains such as ekochist.com, misshon.com, and toutentris.com, where they encounter two main installation methods.
The most successful distribution method involves instructing users to execute malicious commands directly in the macOS Terminal app. This approach is proving particularly effective because it bypasses security feature , which normally prevents unsigned applications from running.
What happens after the malware is executed?
Once executed, this command downloads and executes an installation script that performs several critical functions. The script first downloads an AppleScript file named “update” to the temporary directory, which then performs anti-virtualization checks to avoid detection in sandbox environments.
The malware establishes persistence through a sophisticated multi-component system that includes three key files. The main stealer binary (.helper) performs the actual data collection, while a monitoring script ([.]agent) runs continuously to detect user login sessions. A LaunchDaemon (com[.]finder[.]helper[.]plist) ensures that the malware survives system reboots by automatically launching the monitoring script at boot.
The persistence mechanism creates an endless loop where the .agent script continuously monitors for active user sessions and executes the .helper binary in the appropriate user interface. This design ensures consistent operation while maintaining a low profile, as the malware operates through legitimate system processes.
See also: Malicious npm packages mimic Flashbots & steal wallet keys
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Data extraction is performed via compressed ZIP files sent via HTTP POST requests to command and control servers (with custom headers containing unique identifiers for each infected system).
Atomic Stealer's comprehensive data collection capabilities, combined with sophisticated evasion and persistence mechanisms, make it a formidable threat to macOS users who download software from untrusted sources. Apple recommends downloading software only from official company sites.
