Campaign record
AMOS behind a fingerprint gate
Atomic Stealer delivered by fingerprint-gated fake macOS download pages
- Status as last assessed
- Active
- First seen
- Unrecorded
- Last seen
- Unrecorded
- Indicators
- 17
- Sources
- 1
- Targets
- macOS
- Fake software download page
- AMOS (Atomic macOS Stealer)
- MacSync
- Traffic distribution system (TDS)
Original research
- Microsoft Threat Intelligence2026-08-05Vendor researchFirst account
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
Microsoft Threat Intelligence tracked a cluster of more than 250 look-alike download domains distributing macOS information stealers, among them MacSync and Atomic Stealer. Many names come from a generator pairing the token "file" with two dictionary words, across .com, .sbs and .online, though some place it elsewhere or omit it. Early pages handed the paste-into-Terminal instruction to any visitor; the operators later put a small JavaScript profiler in front, reading navigator, screen and WebGL values, timezone, iframe and touch state, plus tripwires for an open developer console and hooked prototypes, then posting the result back for a server-side ruling. Requests that fail receive a blank shell, a bogus VPN-extension page or an unrelated business site, so a benign answer proves little. Those that pass see a forged Verified Publisher badge, spoofed GitHub styling and a one-click Terminal command ending in Atomic Stealer.
Execution mechanisms
The only execution mechanism any published account describes for this campaign is Terminal paste (macOS) (T1059.004), which 8 of the 44 published campaigns in this corpus also record (18%).
Indicators
17 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator. No observation date is recorded for any of them.
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “AMOS behind a fingerprint gate”, campaign ID ee88ee33, retrieved 2026-08-07, snapshot fb0eed7.
https://clickfixreport.com/campaigns/ee88ee33/macos-clickfix-fingerprint-gate-amos
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.