[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fifq4dd_VQxJzutZ2mYvijxQI6YJYoacHDu67vzs_3PA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"aa54153d-ba99-4c7b-88db-b47a71b7b286","amos-stealer-harvests-macos-credentials-via-social-engineering","abe49990-e758-4ce6-a227-bd16f5819673","Amos Stealer Harvests macOS Credentials via Social Engineering","Amos Stealer exploits user trust through deceptive downloads and social engineering to gain a foothold on macOS systems, highlighting the critical risk posed by malware that blends into legitimate user behavior. Once installed, it silently abuses native macOS utilities like curl and AppleScript — tools users and defenders may not flag as suspicious — to harvest and exfiltrate sensitive credentials, Keychain files, and session cookies. This matters because compromised session tokens and Keychain data can lead to full account takeovers across personal and enterprise services without requiring a password. The attack demonstrates that endpoint security cannot rely solely on patch management; user behavior and download hygiene are equally critical layers of defense.","**Immediate actions:**\n- Enable Gatekeeper and System Integrity Protection (SIP) on all macOS endpoints to block unsigned or unverified software from executing.\n- Audit and restrict which applications are permitted to access the macOS Keychain via System Settings > Privacy & Security.\n- Revoke and rotate all credentials, session tokens, and API keys if a compromise is suspected.\n\n**Long-term improvements:**\n- Deploy an Endpoint Detection and Response (EDR) solution capable of detecting abnormal use of native macOS utilities like curl, osascript, and AppleScript.\n- Enforce application allowlisting to prevent unauthorized or deceptively named executables from running on managed devices.\n- Implement a phishing-resistant MFA standard (e.g., FIDO2\u002FWebAuthn) across all critical accounts to limit damage from stolen credentials.\n\n**Detection measures:**\n- Monitor and alert on unusual outbound network connections initiated by scripting utilities (curl, osascript) to external IP addresses or unfamiliar domains.\n- Configure macOS Unified Logging and forward logs to a SIEM to detect access to Keychain files or bulk file compression activity by unexpected processes.\n- Conduct regular security awareness training focused on safe download practices and recognizing social engineering lures targeting macOS users.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 9: Email and Web Browser Protections","CIS Control 14: Security Awareness and Skills Training","NIST SP 800-53 AC-3: Access Enforcement","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 AU-12: Audit Record Generation","NIST SP 800-53 IA-5: Authenticator Management","NIST CSF DE.CM-1: Network Monitoring","GDPR Article 32: Security of Processing (for organizations handling EU personal data)","MITRE ATT&CK T1555.001: Keychain Access","MITRE ATT&CK T1041: Exfiltration Over C2 Channel","MITRE ATT&CK T1059.002: AppleScript Execution","published","2026-06-16T18:21:25.592208+00:00","2026-06-16T18:21:25.266+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fhackread.com\u002Famos-stealer-macos-keychain-files-browser-passwords\u002F","amos-stealer-targets-macos-keychain-files-and-browser-passwords-4383fa","Amos Stealer Targets macOS Keychain Files and Browser Passwords",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":40,"name":41,"slug":42,"description":43,"color":44},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":46,"name":47,"slug":48,"description":49,"color":50},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]