Amos Stealer Harvests macOS Credentials via Social Engineering
Amos Stealer exploits user trust through deceptive downloads and social engineering to gain a foothold on macOS systems, highlighting the critical risk posed by malware that blends into legitimate user behavior. Once installed, it silently abuses native macOS utilities like curl and AppleScript — tools users and defenders may not flag as suspicious — to harvest and exfiltrate sensitive credentials, Keychain files, and session cookies. This matters because compromised session tokens and Keychain data can lead to full account takeovers across personal and enterprise services without requiring a password. The attack demonstrates that endpoint security cannot rely solely on patch management; user behavior and download hygiene are equally critical layers of defense.
Tactical Insight
Immediate actions
- Enable Gatekeeper and System Integrity Protection (SIP) on all macOS endpoints to block unsigned or unverified software from executing.
- Audit and restrict which applications are permitted to access the macOS Keychain via System Settings > Privacy & Security.
- Revoke and rotate all credentials, session tokens, and API keys if a compromise is suspected.
Long-term improvements
- Deploy an Endpoint Detection and Response (EDR) solution capable of detecting abnormal use of native macOS utilities like curl, osascript, and AppleScript.
- Enforce application allowlisting to prevent unauthorized or deceptively named executables from running on managed devices.
- Implement a phishing-resistant MFA standard (e.g., FIDO2/WebAuthn) across all critical accounts to limit damage from stolen credentials.
Detection measures
- Monitor and alert on unusual outbound network connections initiated by scripting utilities (curl, osascript) to external IP addresses or unfamiliar domains.
- Configure macOS Unified Logging and forward logs to a SIEM to detect access to Keychain files or bulk file compression activity by unexpected processes.
- Conduct regular security awareness training focused on safe download practices and recognizing social engineering lures targeting macOS users.