macOS Under Siege: 2,800+ Websites Used in Stealthy AMOS Malware Offensive
A newly uncovered cyber operation is targeting macOS users through a widespread network of over 2,800 compromised websites. At the heart of the attack is AMOS (Atomic macOS Stealer), a highly advanced malware engineered to harvest confidential data from Apple systems with precision.
Dubbed “MacReaper” by analysts, the campaign first came to light when security teams found traces on a hacked Brazilian news platform. Further investigation revealed a vast and coordinated effort aimed squarely at Mac users worldwide.
Researchers at BadByte told Cyber Security News that the attackers are employing a deceptive technique known as “ClickFix” (also referred to as “ClearFix”). This method selectively targets macOS visitors by displaying phony Google reCAPTCHA pop-ups. These fake prompts are designed to appear legitimate but instead trigger harmful actions behind the scenes.
The attack also incorporates EtherHiding, an obfuscation trick that disguises malicious payloads using Binance’s infrastructure, making detection even harder. Indicators of compromise (IOCs) include suspicious domains like technavix[.]cloud and salorttactical[.]top.
“This is among the most advanced Apple-targeted social engineering campaigns we’ve encountered this year,” noted the lead researcher who uncovered the scheme.
How ClickFix Works:
The method cleverly abuses the user interface by copying disguised shell commands to the clipboard through fake verification boxes. These commands are then unwittingly pasted into Terminal, effectively bypassing browser defenses and leveraging user trust in familiar online elements.
This campaign represents a serious evolution in how cybercriminals target Apple’s ecosystem, blending technical stealth with psychological manipulation.

AMOS Malware Campaign Exposes Deep Flaws in macOS Trust Model
An alarming cyber assault is exploiting trust in familiar interfaces to hijack Apple computers with surgical precision. Researchers have identified a new wave of attacks leveraging over 2,800 hijacked websites to deliver Atomic Stealer—or AMOS—a potent piece of malware that quietly infiltrates macOS systems and drains them of sensitive information.
What makes this operation particularly insidious is its design to mimic legitimate Apple experiences. The phishing component doesn’t just look real—it behaves like it. The interface even includes macOS-native keyboard instructions, engineered to lull users into compliance.
From Click to Compromise
Victims are funneled through fake reCAPTCHA prompts tailored exclusively to Mac users. Once they click the deceptive “I’m not a robot” checkbox, a hidden payload is copied directly to their clipboard—typically a Terminal command. The site then instructs the user to open their Terminal and paste it in, believing it’s part of a routine verification step.
Unknowingly, this command initiates a background download and installation of AMOS, granting the attackers full access to:
- macOS Keychain passwords
- Browser-stored credentials and cookies
- Cryptocurrency wallets
- System profiling data
- Files from Desktop and Documents folders
The attack goes undetected thanks in part to EtherHiding—a cutting-edge evasion strategy that stores malicious code within smart contracts on the Binance Smart Chain (BSC). This use of decentralized infrastructure allows the campaign to bypass traditional takedown efforts, since blockchain content cannot be easily removed or modified by authorities or security vendors.
AMOS: Weaponized and Commercialized
AMOS is no off-the-shelf malware. Sold as a subscription-based service for up to $3,000/month via Telegram, it’s backed by a well-supported criminal ecosystem. This “malware-as-a-service” model means buyers don’t need technical skills—just money and malicious intent.
Once active, AMOS siphons:
- Keychain credentials used by macOS for account authentication
- Autofill and login data from browsers like Chrome and Firefox
- Private keys and recovery phrases from over 50 crypto wallets
- Detailed system metadata for profiling victims
- User files, often exfiltrated under the guise of harmless permissions
Targeted with Precision
The campaign is engineered to ignore Windows and Linux systems entirely. Using user-agent sniffing, it ensures only Mac users are exposed to the malicious payload—an uncommon level of targeting that reflects both confidence and sophistication.
How to Stay Safe on macOS
Security professionals urge Mac users to adopt these precautions immediately:
- Never paste Terminal commands from websites—no exceptions
- Be skeptical of CAPTCHA pop-ups that request unexpected actions
- Keep your OS and apps fully updated
- Use reputable endpoint protection software that monitors for clipboard abuse and command-line activity
- Configure System Settings to allow apps only from the App Store
Rethinking macOS Security
This campaign is a wake-up call: Apple’s platform is no longer an obscure or impractical target for cybercriminals. With tools like AMOS lowering the barrier to entry for attackers, macOS users can no longer rely on reputation alone for protection.




