HomeSecurityAtomic macOS: New attack steals data via Terminal

Atomic macOS: New attack steals data via Terminal

New analysis of Atomic macOS Stealer (AMOS) shows that attackers don't need a complex exploit to bypass a Mac's defenses. All they need is a convincing website and a command that the user will copy into Terminal, believing they are installing a useful tool.

Atomic macOS malware

The SANS Internet Storm Center, published on August 2, is based on a laboratory infection on July 31. The incident captures a modern version of social engineering, where the victim performs the first step of the attack alone.

See also: Atomic Stealer: Appears as cracked software and targets macOS

How the Atomic macOS attack begins

According to the analysis, the chain began with a page that appeared to be a “toolbox for macOS.” The site asked the visitor to paste text into a Terminal window. However, the text was a command that downloaded and installed Atomic macOS, rather than a legitimate utility.

The technique exploits a familiar deception pattern: the instruction is presented as a simple fix or quick installation, while executing it gives the attacker access to the local environment. In the lab, the command was executed twice, followed by entering the account password.

The double execution created repetitive traffic and possibly two different installation locations. SANS detected files in a temporary directory, as well as persistent mechanisms within the user's application support folder. Thus, simply deleting the original file is not necessarily sufficient to remove the threat.

Atomic macOS attack via Terminal

What Atomic macOS looks for on the computer

The communication activity recorded included separate stages for credentials, browsers, messaging apps, and cryptocurrency wallets. Requests to the command and control server showed that Atomic macOS was gathering device information and local data before requesting subsequent tasks.

Technical traces include universal architecture binaries for Intel and Apple Silicon processors, as well as shell scripts stored in temporary paths. SANS also captured communication over plain HTTP, with paths corresponding to device registration, data collection, and task download.

Intrusion indicators are useful for defense teams, but are not proof of infection in themselves. The search should be combined with checking processes, startup items, and unusual outbound connections, especially after using a suspicious Terminal command.

Choosing Terminal as the starting point is particularly important. A command executed by the user himself may appear as an "authorized" action, even though it comes from a malicious page. This reduces the value of warnings based solely on the file's origin.

After the first run, Atomic macOS may remain active in paths that resemble regular Apple support items. File names and locations are not enough to make a firm conclusion; comparison to a known clean system and checking their signature and behavior are needed.

In a corporate environment, the event should be treated as a potential credential exposure rather than a simple computer infection. Isolating the device, revoking active sessions, and changing passwords from a trusted medium limit the scope for second access.

Logging DNS requests, HTTP connections, and new files in a user’s folders helps clarify the duration of the presence. At the same time, security teams can translate exposure indicators into detection rules without indiscriminately blocking legitimate services.

Data theft by Atomic Stealer

See also: Mac.c: New macOS stealer promises quick data extraction

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

How to limit the risk

The basic defense is to not paste commands into Terminal when they come from a pop-up, advertisement, or unknown website. Legitimate support instructions should be checked from the manufacturer's official page, not from a random address that appeared in a search.

Administrators can search for recorded SHA-256 fingerprints and paths listed in the SANS report, review recent connections, and reset passwords from a clean device. Browser passwords, service access tokens, and cryptocurrency wallets require special attention.

Mac protection from Atomic macOS

The incident is a reminder that macOS security doesn't just depend on Gatekeeper or built-in tools. Social engineering shifts critical decision-making to the user, which is why education, Terminal logging, and privilege restrictions remain essential measures.

For users, the safest criterion is simple: no command should be executed because a page requests it. Confirming the source and immediately reporting suspicious behavior can prevent further exposure.

See also: Atomic macOS malware adds backdoor mechanism

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS