HomeSecurityAtomic Stealer: Appears as cracked software and targets macOS

Atomic Stealer: Appears as cracked software and targets macOS

A sophisticated malware targeting macOSis exploiting users' widespread desire for free (cracked) software to distribute the infamous Atomic Stealer (AMOS).

Atomic Stealer macOS

This information-stealing malware disguises itself as cracked versions of popular applications, tricking unsuspecting users into thinkingthey are simply downloading free software alternatives.

The campaign represents a significant shift in the cybersecurity landscape, challenging the long-held perception that macOS devices are inherently more secure than their Windows counterparts. As Apple devices gain popularity among professionals and high-value targets, cybercriminals have adapted their tactics to exploit this growing market.

See also: US: Malware campaign targets trade talks with China

Attackers use multiple distribution methods and constantly change their infrastructure to evade detection. The malware’s reach extends far beyond simple data theft, targeting sensitive information such as browser credentials, crypto wallets, Telegram chats, VPN settings, keychain data, Apple notes, and various files.

This comprehensive approach to data collection makes Atomic Stealer particularly dangerous for both individual users and corporate environments . Compromised credentials can lead to broader breaches of the organization. Trend Micro researchers detected this campaign through Managed Detection and Response services, noting the malware’s ability to bypass traditional security measures through social engineering (rather than technical exploits).

Atomic Stealer Distribution

The analysis revealed that the attackers primarily distribute Atomic Stealer through websites such as haxmac.cc, which hosts numerous cracked macOS applications and acts as the initial infection point. The distribution strategy involves redirecting users through a complex network of rotating domains.

See also: Abuse of iCloud Calendar to send phishing emails

Atomic Stealer: Appears as cracked software and targets macOS

These redirectors ultimately lead victims to pages hosted on domains such as ekochist.com, misshon.com, and toutentris.com, where they encounter two main installation methods.

The most successful distribution method involves instructing users to execute malicious commands directly in the macOS Terminal app. This approach is proving particularly effective because it bypasses security feature , which normally prevents unsigned applications from running.

What happens after the malware is executed?

Once executed, this command downloads and executes an installation script that performs several critical functions. The script first downloads an AppleScript file named “update” to the temporary directory, which then performs anti-virtualization checks to avoid detection in sandbox environments.

The malware establishes persistence through a sophisticated multi-component system that includes three key files. The main stealer binary (.helper) performs the actual data collection, while a monitoring script ([.]agent) runs continuously to detect user login sessions. A LaunchDaemon (com[.]finder[.]helper[.]plist) ensures that the malware survives system reboots by automatically launching the monitoring script at boot.

The persistence mechanism creates an endless loop where the .agent script continuously monitors for active user sessions and executes the .helper binary in the appropriate user interface. This design ensures consistent operation while maintaining a low profile, as the malware operates through legitimate system processes.

See also: Malicious npm packages mimic Flashbots & steal wallet keys

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Atomic Stealer: Appears as cracked software and targets macOS

Data extraction is performed via compressed ZIP files sent via HTTP POST requests to command and control servers (with custom headers containing unique identifiers for each infected system).

Atomic Stealer's comprehensive data collection capabilities, combined with sophisticated evasion and persistence mechanisms, make it a formidable threat to macOS users who download software from untrusted sources. Apple recommends downloading software only from official company sites.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS