AMOS ClickFix Attack
Macs are generally considered at less risk for malware due to their proprietary software and, frankly, smaller hold of the market share (at least with computers; iPhones on the other hand…). But less risk is still some risk. And with the growing prevalence of AI use providing a vector, type of operating system is starting to have nothing to do with safety. The most recent example is the ongoing AMOS attack via OpenAI and Grok.
Atomic macOS Stealer (AMOS) itself isn’t new, it was first reported on in 2023. Unlike other AI-generated malware campaigns, this isn’t using prompt injection, but instead is utilizing weaponized AI through a ClickFix attack. A search for common troubleshooting help will result in AI generated guides. The link to the guide looks legitimate but has been produced via search engine optimization (SEO) poisoning, a tactic used to make malicious sites look and act genuine to further the reach of their payload. Often these links will be at the top of a search page, which reduces the likelihood that users will search more thoroughly before clicking on them.
AMOS is an infostealer, the fastest growing cyberthreat of this year, according to an earlier Kapersky report. This family harvests passwords, cookies, documents and other credentials from infected devices and is one of the man-in-the-middle tools for ransomware campaigns. This particular offshoot of the family tree also uses ‘living-off-the-land’ to harvest credentials without a graphical prompt. It employs the native dscl utility to validate the user’s password silently in the background, according to Cyber Security News’ report, which goes into further detail on how AMOS accomplishes its execution.
There are a couple of main takeaways from this news:
SEO poisoning is cross-platform, since it’s a common tactic across Windows compromises as well as macOS. It’s the backbone of malvertising that is so often used in today’s phishing attempts. I’ve reported before on malicious npm and APK packages that use this technique.
But more importantly, follow the age old internet safety rule of do not click an untrusted link. And never comply with a ‘guide’ that urges one to copy and paste anything into a command line or terminal.
It’s easy to say ‘don’t do this if you don’t understand it’ as a warning against falling for phishing or ClickFix schemes, but that has more than a touch of competency bias attached to it. I’ve often stated that computer literacy is dropping. The average person on the street does not know how their device does what it does, nor are they fluent in the language in which many of these codes are written. This is why I write these reports, to help educate the layperson.
Legitimate helpdesk guides will come from the vendor – or at least be included in a subreddit thread – and not an AI-generated result. This campaign is banking on user trust of AI, but that trust is misplaced already considering how often these tools have inaccurate information in their aggregation or contradict themselves. Kapersky’s report on AMOS even states that querying whether or not the actions presented by this attack are safe – while in the chatbox to execute it – will return with a ‘no’. Trust nothing, question everything, and as always, if you’ve gotten in over your head, your friendly neighborhood WISP is here to help.
Posted on LinkedIn, 12/11/25









