Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Collapse
Brand Logo
UDS UDS: $1.87
24h: 6.02%
Trade UDS
Gate.io
Gate.io
UDS / USDT
MEXC
MEXC
UDS / USDT
WEEX
WEEX
UDS / USDT
COINSTORE
COINSTORE
UDS / USDT
Biconomy.com
Biconomy.com
UDS / USDT
BingX
BingX
UDS / USDT
XT.COM
XT.COM
UDS / USDT
Uniswap v3
Uniswap v3
UDS / USDT
PancakeSwap v3
PancakeSwap v3
UDS / USDT

Earn up to 50 UDS per post

Post in Forum to earn rewards!

Learn more
UDS Right

Spin your Wheel of Fortune!

Earn or purchase spins to test your luck. Spin the Wheel of Fortune and win amazing prizes!

Spin now
Wheel of Fortune
selector
wheel
Spin

Paired Staking

Stake $UDS
APR icon Earn up to 50% APR
NFT icon Boost earnings with NFTs
Earn icon Play, HODL & earn more
Stake $UDS
Stake $UDS
UDS Left

Buy UDS!

Buy UDS with popular exchanges! Make purchases and claim rewards!

Buy UDS
UDS Right

Post in Forum to earn rewards!

UDS Rewards
Rewards for UDS holders
Rewards for UDS holders (per post)*
  • 100 - 999 UDS: 0.05 UDS
  • 1000 - 2499 UDS: 0.10 UDS
  • 2500 - 4999 UDS: 0.5 UDS
  • 5000 - 9999 UDS: 1.5 UDS
  • 10000 - 24999 UDS: 5 UDS
  • 25000 - 49999 UDS: 10 UDS
  • 50000 - 99 999 UDS: 25 UDS
  • 100 000 UDS or more: 50 UDS
*

Rewards are credited at the end of the day. Limited to 5 payable posts per day, 50 K holders - 3 posts per day, 100K holders - 2 posts per day. Staked UDS gives additional coefficient up to X1.5

  1. Home
  2. Crypto-Detective
  3. [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities

[WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities

Scheduled Pinned Locked Moved Crypto-Detective
40 Posts 15 Posters 358 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
This topic has been deleted. Only users with topic management privileges can see it.
  • lingriidddL lingriiddd

    apple.webp

    Hey everyone,
    Just a heads-up about something nasty floating around — AMOS (a.k.a. Atomic macOS Stealer) just leveled up big time. Originally it was mainly grabbing crypto wallets and passwords, but now it’s got a remote access module that basically lets attackers take over your system like it’s their own. Yup, full control — even after a reboot.

    Researcher g0njxa broke down the latest version, and here’s what it can do now:

    🔹 Executes attacker commands directly on your machine
    🔹 Hides from analysis in virtual machines/sandboxes
    🔹 Auto-launches every time your Mac boots up
    🔹 Drops hidden .helper and .agent files, launched via LaunchDaemon with system-level privileges 😨

    That means the attackers can:

    — Install even more malware
    — Log your keystrokes
    — Pivot deeper into your network

    AMOS has been around since at least 2023, but it started off spreading through cracked apps. Now it’s being used in targeted phishing attacks, especially against freelancers and crypto holders. Victims are getting fake job offers or collab requests with weaponized attachments.

    🌍 The latest wave has already hit users in 120+ countries, including the US, Canada, UK, Italy, France, and more.

    TL;DR: If you’re getting random "job offers" with attachments or are working in crypto/web3 — be very careful right now. And maybe audit your LaunchDaemons while you’re at it.

    Stay safe out there.
    #crypto #coin #cryptocurrency #AMOS

    M Offline
    M Offline
    MD SANI
    wrote on last edited by
    #17

    @lingriiddd Auditing LaunchDaemons and checking for suspicious .helper or .agent files is a must right now. The fact that AMOS can bypass sandbox detection shows how advanced it’s become. Mac users really need to stay extra cautious these days

    1 Reply Last reply
    0
    • N Offline
      N Offline
      Nayeem Islam
      wrote on last edited by
      #18

      Thanks for sharing this important update. It’s scary how these fake job offers are now being used to target freelancers and crypto users. If something feels off, don’t open the file — report and delete it right away. Better to stay safe than sorry!

      1 Reply Last reply
      0
      • J Offline
        J Offline
        Jibon_RX
        wrote on last edited by
        #19

        Wow, this AMOS update is scary. Thanks for the heads-up—really need to double-check my Mac's security settings now.

        1 Reply Last reply
        0
        • S Offline
          S Offline
          Smith
          wrote on last edited by
          #20

          Appreciate this info! It’s crazy how these attackers keep finding new ways to exploit users, especially in the crypto space.

          D 1 Reply Last reply
          0
          • D Offline
            D Offline
            Dave
            wrote on last edited by
            #21

            Honestly, this is one of the most useful warnings I’ve seen today. Time to be paranoid for the right reasons.

            1 Reply Last reply
            0
            • J Offline
              J Offline
              Jibon_RX
              wrote on last edited by
              #22

              Appreciate the reminder to stay vigilant. These attackers are ruthless, and we have to protect ourselves.

              1 Reply Last reply
              0
              • D Offline
                D Offline
                Dave
                wrote on last edited by
                #23

                Crazy how malware campaigns have gone global so fast—120+ countries already??

                S 1 Reply Last reply
                0
                • D Dave

                  Crazy how malware campaigns have gone global so fast—120+ countries already??

                  S Offline
                  S Offline
                  Smith
                  wrote on last edited by
                  #24

                  @Dave
                  I wish more people took these warnings seriously. Prevention is much easier than dealing with an infected system.

                  J 1 Reply Last reply
                  0
                  • S Smith

                    @Dave
                    I wish more people took these warnings seriously. Prevention is much easier than dealing with an infected system.

                    J Offline
                    J Offline
                    Jibon_RX
                    wrote on last edited by
                    #25

                    @Smith
                    Big thanks to researchers like g0njxa who help us understand threats like this.

                    1 Reply Last reply
                    0
                    • N Offline
                      N Offline
                      Nahiar806
                      wrote on last edited by
                      #26

                      LaunchDaemons are no joke — once malware gets in there with root privileges, it’s game over. Everyone on macOS should audit theirs ASAP.

                      1 Reply Last reply
                      0
                      • A Offline
                        A Offline
                        alex
                        wrote on last edited by
                        #27

                        These attackers are getting way too sophisticated. Remote access + persistence = nightmare fuel

                        1 Reply Last reply
                        0
                        • M Offline
                          M Offline
                          Maxwell
                          wrote on last edited by
                          #28

                          Freelancers are such easy targets now. If someone sends you a DM about a 'collab' and there's a file attached — assume it’s malicious

                          1 Reply Last reply
                          0
                          • rafihasanR Offline
                            rafihasanR Offline
                            rafihasan
                            wrote on last edited by
                            #29

                            One more reason to stop downloading cracked software. That free plugin might just cost you your wallet

                            1 Reply Last reply
                            0
                            • J Offline
                              J Offline
                              Jibon_RX
                              wrote on last edited by
                              #30

                              Crypto and macOS users need to be on high alert. These phishing tactics are getting too real.

                              1 Reply Last reply
                              0
                              • S Smith

                                Appreciate this info! It’s crazy how these attackers keep finding new ways to exploit users, especially in the crypto space.

                                D Offline
                                D Offline
                                Dave
                                wrote on last edited by
                                #31

                                @Smith
                                Definitely going to stop downloading cracked apps altogether. Not worth the risk anymore.

                                1 Reply Last reply
                                0
                                • S Offline
                                  S Offline
                                  Smith
                                  wrote on last edited by
                                  #32

                                  This is the kind of info that needs to be spread in every crypto community right now.

                                  1 Reply Last reply
                                  0
                                  • rafihasanR Offline
                                    rafihasanR Offline
                                    rafihasan
                                    wrote on last edited by
                                    #33

                                    If AMOS can bypass VMs and sandboxes, even malware analysts are at risk. That’s wild.”

                                    1 Reply Last reply
                                    0
                                    • J Offline
                                      J Offline
                                      Jibon_RX
                                      wrote on last edited by
                                      #34

                                      I checked my system and luckily everything’s clean, but still feeling uneasy about those fake job DMs.

                                      1 Reply Last reply
                                      0
                                      • D Offline
                                        D Offline
                                        Dave
                                        wrote on last edited by
                                        #35

                                        These attackers exploiting trust in the freelance community is honestly the worst part. Be careful out there!

                                        1 Reply Last reply
                                        0
                                        • S Offline
                                          S Offline
                                          Smith
                                          wrote on last edited by
                                          #36

                                          Thank you for posting this. Practical advice and real-world risks explained in a way everyone can understand.

                                          J 1 Reply Last reply
                                          0


                                          Powered by NodeBB Contributors
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups