Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Threat Actors Exploit ChatGPT and Grok Conversations to Deliver AMOS Stealer

On Fri, Dec 5, 2025, Huntress identified a sophisticated cyber campaign utilizing the Atomic macOS Stealer (AMOS). This campaign employs a simple yet effective method of infiltration, exploiting AI-generated content through search engine optimization.

On Fri, Dec 5, 2025, Huntress identified a sophisticated cyber campaign utilizing the Atomic macOS Stealer (AMOS). This campaign employs a simple yet effective method of infiltration, exploiting AI-generated content through search engine optimization.

The attack vector leverages AI conversations on OpenAI’s ChatGPT and xAI’s Grok platforms, manipulated to appear as credible troubleshooting guides. This approach does not require malicious downloads or traditional security warnings, relying instead on search queries, clicks, and copy-paste commands.

The infection method capitalizes on the trustworthiness of search engines, platform legitimacy, and AI-generated authority. Users searching for macOS maintenance queries, such as “clear disk space on macOS,” are directed to discussions on ChatGPT and Grok, which are presented as professional troubleshooting guides.

When users execute the provided Terminal command, it initiates a multi-stage infection process that collects credentials, escalates privileges, and facilitates continuous data exfiltration.

This campaign signifies an evolution in social engineering tactics. Attackers are weaponizing trusted platforms through search result manipulation. The malicious software masquerades as legitimate help, rather than clean software.

On Fri, Dec 5, 2025, Huntress identified a sophisticated cyber campaign utilizing the Atomic macOS Stealer (AMOS).
Angela Waters · Thehackingpost

Huntress confirmed this campaign's widespread nature by reproducing the manipulated search results for various queries, indicating a deliberate effort to target common troubleshooting searches.

The deployment of AMOS involves a bash script requesting the user's system password under the guise of verification. Credentials are validated in the background with the dscl-authonly command, without displaying any system UI prompts.

Once validated, the credentials are stored in plaintext and utilized for administrative control. The malware installs its payload in a hidden directory within the user's home directory, targeting legitimate cryptocurrency wallet applications and replacing them with trojanized versions.

The stealer maintains comprehensive data harvesting capabilities, targeting cryptocurrency wallets, browser credential databases, macOS user Keychain entries, and sensitive files. Persistence is achieved through a LaunchDaemon plist that continuously monitors the active GUI session, relaunching the main binary if terminated.

Advertisement

Detecting this campaign poses significant challenges, as traditional signature-based methods are ineffective. Organizations must focus on monitoring behavioral anomalies, such as unusual credential requests and hidden executables.

End users are at risk due to the attack's reliance on trust in AI-generated content. As AI becomes integral to daily workflows, this attack method may proliferate, emphasizing the need for updated security measures.

This campaign represents a pivotal moment in macOS security, highlighting the importance of distinguishing between platform trust and user-generated content. Future defenses must adapt to target behavioral exploits rather than code vulnerabilities.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories