Live Threat Pulse: 2,847 threats detected in last 24h

menu_book Malware Family

Atomic macOS Stealer (AMOS)

Also known as: AMOS, Atomic Stealer

Atomic macOS Stealer (AMOS) is an infostealer targeting Apple macOS systems. It steals keychain passwords, browser credentials and cookies, and cryptocurrency wallets, and is notable for proving that the infostealer-as-a-service model extends well beyond Windows.

What is Atomic macOS Stealer?

Atomic macOS Stealer, commonly abbreviated AMOS, is a malware-as-a-service infostealer built specifically for macOS. Its emergence challenged the assumption that infostealers are a Windows-only problem.

How AMOS works

AMOS typically arrives via malicious DMG installers, cracked applications, or malvertising. On execution it uses social-engineering prompts to capture the user's macOS password, then extracts keychain secrets, browser credentials and cookies, and cryptocurrency wallet data before exfiltrating them.

Why AMOS matters

AMOS demonstrates that macOS users — often assumed to be lower-risk — are squarely targeted by the credential-theft economy. Its keychain access makes a successful infection especially damaging.

How VantaPrism Tracks Atomic macOS Stealer (AMOS)

VantaPrism's coverage spans macOS-targeting families such as AMOS, so organisations with mixed fleets can detect exposures regardless of the victim's operating system.

Check Your Exposure arrow_forward

Frequently Asked Questions

Do infostealers target Macs?

expand_more
Yes. Atomic macOS Stealer (AMOS) and similar families are built specifically for macOS, stealing keychain secrets, browser data, and crypto wallets.

How does AMOS get the macOS password?

expand_more
AMOS commonly displays a fake system prompt asking the user to enter their password, then uses it to unlock the keychain and extract stored secrets.
← All Glossary Terms Last reviewed: June 2026