Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    In Graphic Detail: Subscriptions are rising at big news publishers – even as traffic shrinks

    ‘An influential seat at the table’: Why Target’s retail media business Roundel is one of the first to test ChatGPT ads

    Ad Tech Briefing: A mid-term report card

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026

      ChatGPT can embrace authoritarian ideas after just one prompt, researchers say

      January 24, 2026
    • Business

      The HDD brand that brought you the 1.8-inch, 2.5-inch, and 3.5-inch hard drives is now back with a $19 pocket-sized personal cloud for your smartphones

      February 12, 2026

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026

      Top 10 cloud computing stories of 2025

      December 22, 2025
    • Crypto

      Metaplanet Reports FY2025 Results as Bitcoin Unrealized Losses Top $1 Billion

      February 17, 2026

      Crypto’s AI Pivot: Hype, Infrastructure, and a Two-Year Countdown

      February 17, 2026

      The RWA War: Stablecoins, Speed, and Control

      February 17, 2026

      Jeffrey Epstein Emails Show Plans to Meet Gary Gensler To Talk Crypto

      February 17, 2026

      Bitcoin Bounce Fades, Q1 Losses Deepen, and New Price Risk Back in Focus

      February 17, 2026
    • Technology

      In Graphic Detail: Subscriptions are rising at big news publishers – even as traffic shrinks

      February 17, 2026

      ‘An influential seat at the table’: Why Target’s retail media business Roundel is one of the first to test ChatGPT ads

      February 17, 2026

      Ad Tech Briefing: A mid-term report card

      February 17, 2026

      AdCP vs. IAB Tech Lab: Inside programmatic advertising’s agentic AI standards showdown

      February 17, 2026

      ChatGPT enters the ad game. Now what?

      February 17, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Atomic macOS infostealer adds backdoor for persistent attacks
    Technology

    Atomic macOS infostealer adds backdoor for persistent attacks

    TechAiVerseBy TechAiVerseJuly 8, 2025No Comments3 Mins Read3 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Atomic macOS infostealer adds backdoor for persistent attacks
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Atomic macOS infostealer adds backdoor for persistent attacks

    Malware analyst discovered a new version of the Atomic macOS info-stealer (also known as ‘AMOS’) that comes with a backdoor, to attackers persistent access to compromised systems.

    The new component allows executing arbitrary remote commands, it survives reboots, and permits maintaining control over infected hosts indefinitely.

    MacPaw’s cybersecurity division Moonlock analyzed the backdoor in Atomic malware after a tip from independent researcher g0njxa, a close observer of infostealer activity.

    “AMOS malware campaigns have already reached over 120 countries, with the United States, France, Italy, the United Kingdom, and Canada among the most affected,” the researchers say.

    “The backdoored version of Atomic macOS Stealer now has the potential to gain full access to thousands of Mac devices worldwide.”

    Circulation of unique Atomic stealer samples
    Source: Moonlock

    Evolution of the Atomic stealer

    The Atomic stealer, first documented in April 2023, is a malware-as-a-service (MaaS) operation promoted on Telegram channels for a hefty subscription of $1,000 per month. It targets macOS files, cryptocurrency extensions, and user passwords stored on web browsers.

    In November 2023, it supported the first-ever expansion of ‘ClearFake’ campaigns onto macOS, while in September 2024, it was spotted in a large-scale campaign by the cybercrime group’ Marko Polo,’ who deployed it on Apple computers.

    Moonlock reports that Atomic has recently shifted from broad distribution channels like cracked software sites, to targeted phishing aimed at cryptocurrency owners, as well as job interview invitations to freelancers.

    The analyzed version of the malware comes with an embedded backdoor, uses of LaunchDaemons to survive reboots on macOS, ID-based victim tracking, and new command-and-control infrastructure.

    Evolution of the Atomic stealer
    Source: Moonlock

    A backdoor into your Mac

    The core backdoor executable is a binary named ‘.helper,’ downloaded and saved in the victim’s home directory as a hidden file post-infection, the researchers say.

    A persistent wrapper script named ‘.agent’ (also hidden) runs ‘.helper’ in a loop as the logged-in user, while a LaunchDaemon (com.finder.helper) installed via AppleScript ensures that ‘.agent’ executes at system startup.

    This action is performed with elevated privileges using the user’s password stolen during the initial infection phase under a false pretext. The malware can then execute commands and change ownership of the LaunchDaemon PLIST to ‘root:wheel’ (superuser level on macOS).

    The backdoor execution chain
    Source: Moonlock

    The backdoor allows the threat actors to execute commands remotely, log key strokes, introduce additional payloads, or explore lateral movement potential.

    To evade detection, the backdoor checks for sandbox or virtual machine environments using ‘system_profiler’ and also features string obfuscation.

    The evolution of Atomic malware shows that macOS users are becoming more attractive targets and malicious campaigns aimed at them are increasingly sophisticated.


    8 Common Threats in 2025

    While cloud attacks may be growing more sophisticated, attackers still succeed with surprisingly simple techniques.

    Drawing from Wiz’s detections across thousands of organizations, this report reveals 8 key techniques used by cloud-fluent threat actors.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleQantas is being extorted in recent data-theft cyberattack
    Next Article Employee gets $920 for credentials used in $140 million bank heist
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    In Graphic Detail: Subscriptions are rising at big news publishers – even as traffic shrinks

    February 17, 2026

    ‘An influential seat at the table’: Why Target’s retail media business Roundel is one of the first to test ChatGPT ads

    February 17, 2026

    Ad Tech Briefing: A mid-term report card

    February 17, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025681 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025263 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025155 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025114 Views
    Don't Miss
    Technology February 17, 2026

    In Graphic Detail: Subscriptions are rising at big news publishers – even as traffic shrinks

    In Graphic Detail: Subscriptions are rising at big news publishers – even as traffic shrinksAfter…

    ‘An influential seat at the table’: Why Target’s retail media business Roundel is one of the first to test ChatGPT ads

    Ad Tech Briefing: A mid-term report card

    AdCP vs. IAB Tech Lab: Inside programmatic advertising’s agentic AI standards showdown

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    In Graphic Detail: Subscriptions are rising at big news publishers – even as traffic shrinks

    February 17, 20263 Views

    ‘An influential seat at the table’: Why Target’s retail media business Roundel is one of the first to test ChatGPT ads

    February 17, 20262 Views

    Ad Tech Briefing: A mid-term report card

    February 17, 20260 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.