Skip to content

Campaign record

AMOS behind a fingerprint gate

Atomic Stealer delivered by fingerprint-gated fake macOS download pages

Status as last assessed
Active
First seen
Unrecorded
Last seen
Unrecorded
Indicators
17
Sources
1
Targets
macOS
  • Fake software download page
  • AMOS (Atomic macOS Stealer)
  • MacSync
  • Traffic distribution system (TDS)

Original research

This page summarises and structures that research; it is not a substitute for the original.

Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.

Summary

Microsoft Threat Intelligence tracked a cluster of more than 250 look-alike download domains distributing macOS information stealers, among them MacSync and Atomic Stealer. Many names come from a generator pairing the token "file" with two dictionary words, across .com, .sbs and .online, though some place it elsewhere or omit it. Early pages handed the paste-into-Terminal instruction to any visitor; the operators later put a small JavaScript profiler in front, reading navigator, screen and WebGL values, timezone, iframe and touch state, plus tripwires for an open developer console and hooked prototypes, then posting the result back for a server-side ruling. Requests that fail receive a blank shell, a bogus VPN-extension page or an unrelated business site, so a benign answer proves little. Those that pass see a forged Verified Publisher badge, spoofed GitHub styling and a one-click Terminal command ending in Atomic Stealer.

Execution mechanisms

The only execution mechanism any published account describes for this campaign is Terminal paste (macOS) (T1059.004), which 8 of the 44 published campaigns in this corpus also record (18%).

Indicators

17 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator. No observation date is recorded for any of them.

Indicators recorded for this campaign, shown defanged
IndicatorTypeRoleAssessmentReport an error
domain, shown defanged for safety: applefilevault dot comdomainLure pageAttacker-controlledReport an error in domain record 9ea4a01a-28d0-4960-ad26-abaf82f66964
domain, shown defanged for safety: apricotfilepoint dot comdomainLure pageAttacker-controlledReport an error in domain record 96bbb9e1-2559-48a2-8e56-e6af2fc91623
domain, shown defanged for safety: bananafastfile dot comdomainLure pageAttacker-controlledReport an error in domain record 3275412b-b44e-40a4-8114-29803e29ca6c
domain, shown defanged for safety: cloudfilebridge dot comdomainLure pageAttacker-controlledReport an error in domain record e808aa26-9d09-4231-97db-dd53716b93d6
domain, shown defanged for safety: cloudsendhub dot comdomainLure pageAttacker-controlledReport an error in domain record 681a3efe-0bdc-438e-89fa-13fe09d79835
domain, shown defanged for safety: filecedarwallet dot onlinedomainLure pageAttacker-controlledReport an error in domain record 6ea65910-a9e0-4647-a87e-e26a1d0ba5b5
domain, shown defanged for safety: filecopperbasket dot sbsdomainLure pageAttacker-controlledReport an error in domain record 5fe3a5bc-5bd6-4384-9aaf-6705cb931952
domain, shown defanged for safety: filecrimsonsignal dot onlinedomainLure pageAttacker-controlledReport an error in domain record cdce0048-921b-45d4-a2fb-bae4ae8682fd
domain, shown defanged for safety: filemarblegarden dot sbsdomainLure pageAttacker-controlledReport an error in domain record 1dc38369-9c46-496a-9078-c20e9f9e1d36
domain, shown defanged for safety: fileoceanhammer dot sbsdomainLure pageAttacker-controlledReport an error in domain record c127ed52-a210-49af-a0f7-87e5e5bcb58f
domain, shown defanged for safety: filerubyfolder dot sbsdomainLure pageAttacker-controlledReport an error in domain record ea3bc477-1437-4d72-8178-62f3cb8c6acd
domain, shown defanged for safety: filevelvettractor dot sbsdomainLure pageAttacker-controlledReport an error in domain record 0bda4b40-bfd9-4e36-8d5b-6d3ba5ca1894
domain, shown defanged for safety: lemonfilewave dot comdomainLure pageAttacker-controlledReport an error in domain record 136e3f76-eca5-47d3-baf4-27c1910ad6b9
domain, shown defanged for safety: limefilescope dot comdomainLure pageAttacker-controlledReport an error in domain record 70ab0dcc-a269-4df6-af22-1eb865d2d581
domain, shown defanged for safety: mangocloudfile dot comdomainLure pageAttacker-controlledReport an error in domain record 21987961-81d1-495b-86e9-cb64a9f855f8
domain, shown defanged for safety: orangesmartfile dot comdomainLure pageAttacker-controlledReport an error in domain record 2651ba9e-625c-4c5b-a127-8d431d0b66e2
domain, shown defanged for safety: syncdatavault dot comdomainLure pageAttacker-controlledReport an error in domain record 716b55e7-0a49-4f58-82f0-4f1d305ebf11

“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.

Not on this record

This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.

Cite as

ClickFixReport, “AMOS behind a fingerprint gate”, campaign ID ee88ee33, retrieved 2026-08-07, snapshot fb0eed7.

https://clickfixreport.com/campaigns/ee88ee33/macos-clickfix-fingerprint-gate-amos

Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.