(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Source link

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Source link

Introduction
This diary provides indicators from an Atomic MacOS (AMOS) stealer infection that I generated in my lab on July 31st, 2026. This was distributed through a web page from getmacouscloud[.]com with instructions to paste text into a macOS Terminal window, supposedly for “macOS toolkit,” but instead the text is a command to retrieve and install AMOS stealer malware.
Of note, I ran the text in the Terminal window twice, because I wanted to make sure I retrieved copies of files in the host’s /tmp directory before entering the user account password. This is why the initial infection traffic is repeated, and also likely why there are two different directories with the AMOS stealer malware persistent on my infected lab host.
Images from the Infection

Shown above: Website with instructions to copy and paste text into a Terminal window, supposedly for a “macOS toolkit” but actually for malware.

Shown above: The malicious text pasted into a Terminal Window on a macOS host.

Shown above: Files from my infected host’s /tmp directory, showing data stolen and other info for AMOS stealer.

Shown above: Examples of AMOS stealer persistent on my infected macOS host.

Shown above: Traffic from the AMOS stealer infection filtered in Wireshark.
Indicators of Compromise
Traffic leading to the getmacouscloud[.]com page on Friday 2026-07-31:
URL from the base64 text provided by getmacouscloud[.]com for the initial download:
URLs from extracted from the payload returned from the initial download:
AMOS stealer C2 traffic – HTTP POST requests over TCP port 80:
AMOS stealer C2 traffic – examples of HTTP GET requests over TCP port 80:
SHA-256 hash: b9ec3261d633c289e51c5fa8842af4350efe68446df39cb995de82e0941d0f3c
SHA-256 hash: 13b868b3ea8b492e7fbab1ca04535c53d0930650185b5a082cd59c1974689cd5
SHA-256 hash: 9f25ec533cb23d020e568fb771500d7776b1300f07119ad9d0876f4329ce22ab
SHA-256 hash: 0a03cf18de28017c0ea591dffc380a6b41fedd2acc3a39e901e58d9188c01836
SHA-256 hash: 01a0d5332b09bb299f7784bf0d0c43c4199269ed6a0712377279eeb999847d20
—
Bradley Duncan
brad [at] malware-traffic-analysis.net

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Source link