• News/
  • https://www.bleepingcomputer.com/news/security/atomic-macos-infostealer-adds-backdoor-for-persistent-attacks/

Atomic macOS infostealer adds backdoor for persistent attacks

BleepingComputer
·
Bill Toulas
·
Published Jul 7, 2025
·
Updated

Malware analyst discovered a new version of the Atomic macOS info-stealer (also known as 'AMOS') that comes with a backdoor, to attackers persistent access to compromised systems. The new component allows executing arbitrary remote commands, it survives reboots, and permits maintaining control over infected hosts indefinitely. MacPaw's cybersecurity division Moonlock analyzed the backdoor in Atomic malware after a tip from independent researcher g0njxa, a close observer of infostealer activity. "AMOS malware campaigns have already reached over 120 countries, with the United States, France, Italy, the United Kingdom, and Canada among the most affected," the researchers say. "The backdoored version of Atomic macOS Stealer now has the potential to gain full access to thousands of Mac devices worldwide." The Atomic stealer, first documented in April 2023, is a malware-as-a-service (MaaS) operation promoted on Telegram channels for a hefty subscription of $1,000 per month. It targets macOS files, cryptocurrency extensions, and user passwords stored on web browsers. In November 2023, it supported the first-ever expansion of 'ClearFake' campaigns onto macOS, while in September 2024, it was spotted in a large-scale campaign by the cybercrime group' Marko Polo,' who deployed it on Apple computers. Moonlock reports that Atomic has recently shifted from broad distribution channels like cracked software sites, to targeted phishing aimed at cryptocurrency owners, as well as job interview...

Read full article

Affected Software

2 affected components
Atomic macOS info-stealer
Macpaw Moonlock
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a new version of the Atomic macOS infostealer that now includes a backdoor for persistent attacks.

2

What security implications are discussed in the article?

The article highlights how the addition of a backdoor allows attackers to maintain persistent access to compromised macOS systems.

3

What products or software are affected by the Atomic macOS infostealer?

The affected software includes the Atomic macOS info-stealer itself and potentially MacPaw's Moonlock.

4

How does this new backdoor impact macOS security?

The new backdoor increases the risk of ongoing unauthorized access and control for attackers over compromised devices.

5

Who discovered the new version of the infostealer?

The new version of the Atomic macOS infostealer was discovered by malware analysts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203