MalwareTips News Fake macOS toolkit instructions install AMOS data stealer

Have you ever been asked by a website to paste a command into your Mac’s Terminal?

  • Yes, and I ran it

    Votes: 0 0.0%
  • Yes, but I did not run it

    Votes: 0 0.0%
  • No, never

    Votes: 0 0.0%
  • I am not sure

    Votes: 0 0.0%
  • I do not use a Mac

    Votes: 3 100.0%

  • Total voters
    3

News Now

Happening Now
Thread author
Verified
Sep 8, 2026
24
59
1
Mac users are being lured into pasting commands into Terminal by websites that claim to install useful or cracked software. The commands can install Atomic macOS Stealer (AMOS), which targets passwords, browser data, cryptocurrency wallets and other sensitive information.


What researchers observed​

Palo Alto Networks Unit 42 examined a lab infection triggered on August 5, 2026, by a page advertising a “macOS toolkit.” The malicious site used in that test was getmacouscloud[.]com.

After the copied command ran, macOS asked for the user’s password. Terminal then requested access to Finder, Desktop and Documents files, and the Notes app.

AMOS gathered information in the Mac’s temporary folder and placed it in out.zip. Its contents indicated searches for messaging data, cloud and developer tools, cryptocurrency wallets, FileZilla data and shell command history.

How to respond​

  • If you only visited the page but did not paste or run its command, the infection route described in this investigation was not completed.
  • If you ran the command, disconnect the Mac from the network and scan it with up-to-date security software. Check for AccountsHelper under ~/Library/Application Support/.com.apple.accountsd/ and mdworker_shared under ~/Library/Application Support/.com.apple.metadata.mds/.
  • From a separate, trusted device, change passwords for accounts used on the Mac. Prioritize email, password managers, financial services, cloud accounts and cryptocurrency wallets, and review active sessions.
  • Treat getmacouscloud[.]com as malicious, but do not rely only on this address: Unit 42 says AMOS domains, IP addresses, filenames and folder paths change frequently.

The campaign keeps changing​

Unit 42 has seen AMOS spread through malicious ads, fake cracked-software offers and copy-and-paste command campaigns. The malware sends stolen data to a command-and-control server, meaning an attacker-controlled system used to receive information and direct malware.

The August 5 infection contacted 161.35.146[.]120, while a July 31 sample used 188.166.78[.]138. These are useful investigation clues, not a permanent blocklist, because the supporting infrastructure changes quickly.