Malware analyst discovered a new version of the Atomic macOS info-stealer (also known as 'AMOS') that comes with a backdoor, to attackers persistent access to compromised systems. The new component allows executing arbitrary remote commands, it survives reboots, and permits maintaining control over infected hosts indefinitely. MacPaw's cybersecurity division Moonlock analyzed the backdoor in Atomic malware after a tip from independent researcher g0njxa, a close observer of infostealer activity. "AMOS malware campaigns have already reached over 120 countries, with the United States, France, Italy, the United Kingdom, and Canada among the most affected," the researchers say. "The backdoored version of Atomic macOS Stealer now has the potential to gain full access to thousands of Mac devices worldwide." The Atomic stealer, first documented in April 2023, is a malware-as-a-service (MaaS) operation promoted on Telegram channels for a hefty subscription of $1,000 per month. It targets macOS files, cryptocurrency extensions, and user passwords stored on web browsers. In November 2023, it supported the first-ever expansion of 'ClearFake' campaigns onto macOS, while in September 2024, it was spotted in a large-scale campaign by the cybercrime group' Marko Polo,' who deployed it on Apple computers. Moonlock reports that Atomic has recently shifted from broad distribution channels like cracked software sites, to targeted phishing aimed at cryptocurrency owners, as well as job interview...
Atomic macOS infostealer adds backdoor for persistent attacks
BleepingComputer
·Bill Toulas
·Published Jul 7, 2025
·Updated
Affected Software
2 affected components
Atomic macOS info-stealer
Macpaw Moonlock
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a new version of the Atomic macOS infostealer that now includes a backdoor for persistent attacks.
2
What security implications are discussed in the article?
The article highlights how the addition of a backdoor allows attackers to maintain persistent access to compromised macOS systems.
3
What products or software are affected by the Atomic macOS infostealer?
The affected software includes the Atomic macOS info-stealer itself and potentially MacPaw's Moonlock.
4
How does this new backdoor impact macOS security?
The new backdoor increases the risk of ongoing unauthorized access and control for attackers over compromised devices.
5
Who discovered the new version of the infostealer?
The new version of the Atomic macOS infostealer was discovered by malware analysts.