216.73.217.22

AI-Poisoning & AMOS Stealer: How Trust Became the Biggest Mac Threat

· Published 10/12/2025 12:06 · Modified 21/12/2025 18:56

Export JSON

Essential information

Published
10/12/2025 12:06
Modified
21/12/2025 18:56
Tags
2025-12-10 ai-poisoning amos atomic macos stealer chatgpt credential harvesting grok macos persistence seo manipulation social engineering stealer
Related entities
8 observables, 2 malware, 2 others

Description

A sophisticated malware campaign exploits user trust in AI platforms to deliver the . Attackers use SEO poisoning to surface malicious and conversations offering 'helpful' disk cleanup advice. These conversations contain Terminal commands that, when executed, deploy , a multi-stage malware that harvests credentials, escalates privileges, and establishes . The attack bypasses traditional security measures by leveraging legitimate platforms and user behavior, making it particularly insidious. targets cryptocurrency wallets, browser data, and system information, exfiltrating sensitive data to attacker-controlled servers. This campaign represents a significant evolution in techniques, exploiting the growing reliance on AI assistants for technical guidance.

External references