Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Exploiting Clickfix: AMOS macOS Stealer Evades Security to Deploy Malicious Code

An Atomic macOS Stealer (AMOS) variant campaign has been identified, indicating advanced multi-platform social engineering attacks.

An Atomic macOS Stealer (AMOS) variant campaign has been identified, indicating advanced multi-platform social engineering attacks.

This campaign exploits typo-squatted domains impersonating Spectrum, a U.S.-based telecommunications provider, to deliver payloads tailored to the victim's operating system.

macOS users are targeted with a malicious shell script designed to extract system passwords and deploy an AMOS variant for further exploitation.

The attack involves luring victims to typo-squatted domains such as panel-spectrum[.]net and spectrum-ticket[.]net, where they are prompted to click on an “Alternative Verification” option. This action copies a malicious command to the clipboard, providing platform-specific instructions.

Non-macOS user agents receive a PowerShell command from a command-and-control (C2) server, while macOS users are given a Bash command that downloads a script containing a harmful attack chain.

The script harvests the victim’s password, validates it, and stores it. A malicious binary is downloaded, bypassing macOS security using the stolen password, and executes the AMOS variant.

This method, which leverages legitimate tools, reduces detection by traditional security solutions, allowing attackers to steal credentials and potentially facilitate further intrusions.

This AMOS campaign poses significant risks, especially for corporate users whose credentials could grant access to sensitive resources. The use of native macOS commands to bypass security highlights the difficulty of detecting such threats.

An Atomic macOS Stealer (AMOS) variant campaign has been identified, indicating advanced multi-platform social engineering attacks.
Peter Collins · Thehackingpost

Organizations should enhance user awareness to recognize deceptive tactics, enforce system integrity protections, and restrict unsigned script execution. Threat hunting for unusual activities and known AMOS indicators can help identify compromises early.

Indicator Type Value Use

Domain panel-spectrum[.]net Clickfix Delivery

Domain spectrum-ticket[.]net Clickfix Delivery

Domain cf-verifi.pages[.]dev Command and Control

Domain applemacios[.]com Command and Control

Advertisement

MD5 Hash eaedee8fc9fe336bcde021bf243e332a AMOS Variant

URL https://cf-verifi.pages[.]dev/i.txt Contacted URLs

URL https://applemacios[.]com/getrur/install.sh Contacted URLs

URL https://applemacios[.]com/getrur/update Contacted URLs

Domain rugmel[.]cat Clickfix Indicator of Future Attack

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories