<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[[WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities]]></title><description><![CDATA[<p dir="auto"><img src="/forum/assets/uploads/files/1752061706967-apple.webp" alt="apple.webp" class=" img-fluid img-markdown" /></p>
<p dir="auto">Hey everyone,<br />
Just a heads-up about something nasty floating around — AMOS (a.k.a. Atomic macOS Stealer) just leveled up big time. Originally it was mainly grabbing crypto wallets and passwords, but now it’s got a remote access module that basically lets attackers take over your system like it’s their own. Yup, full control — even after a reboot.</p>
<p dir="auto">Researcher g0njxa broke down the latest version, and here’s what it can do now:</p>
<p dir="auto"><img src="https://undeads.com/forum/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=1a091c6c954" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> Executes attacker commands directly on your machine<br />
<img src="https://undeads.com/forum/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=1a091c6c954" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> Hides from analysis in virtual machines/sandboxes<br />
<img src="https://undeads.com/forum/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=1a091c6c954" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> Auto-launches every time your Mac boots up<br />
<img src="https://undeads.com/forum/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=1a091c6c954" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> Drops hidden .helper and .agent files, launched via LaunchDaemon with system-level privileges <img src="https://undeads.com/forum/assets/plugins/nodebb-plugin-emoji/emoji/android/1f628.png?v=1a091c6c954" class="not-responsive emoji emoji-android emoji--fearful" style="height:23px;width:auto;vertical-align:middle" title="😨" alt="😨" /></p>
<p dir="auto">That means the attackers can:</p>
<p dir="auto">— Install even more malware<br />
— Log your keystrokes<br />
— Pivot deeper into your network</p>
<p dir="auto">AMOS has been around since at least 2023, but it started off spreading through cracked apps. Now it’s being used in targeted phishing attacks, especially against freelancers and crypto holders. Victims are getting fake job offers or collab requests with weaponized attachments.</p>
<p dir="auto"><img src="https://undeads.com/forum/assets/plugins/nodebb-plugin-emoji/emoji/android/1f30d.png?v=1a091c6c954" class="not-responsive emoji emoji-android emoji--earth_africa" style="height:23px;width:auto;vertical-align:middle" title="🌍" alt="🌍" /> The latest wave has already hit users in 120+ countries, including the US, Canada, UK, Italy, France, and more.</p>
<p dir="auto">TL;DR: If you’re getting random "job offers" with attachments or are working in crypto/web3 — be very careful right now. And maybe audit your LaunchDaemons while you’re at it.</p>
<p dir="auto">Stay safe out there.<br />
#crypto #coin #cryptocurrency #AMOS</p>
]]></description><link>https://undeads.com/forum/topic/53/warning-amos-malware-just-got-a-major-upgrade-now-with-full-remote-access-capabilities</link><generator>RSS for Node</generator><lastBuildDate>Sun, 05 Apr 2026 04:34:50 GMT</lastBuildDate><atom:link href="https://undeads.com/forum/topic/53.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 09 Jul 2025 11:49:19 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 14:42:24 GMT]]></title><description><![CDATA[<p dir="auto">Keep your MacOS updated, don’t trust random files, and always check file permissions. This new AMOS variant means business</p>
]]></description><link>https://undeads.com/forum/post/391</link><guid isPermaLink="true">https://undeads.com/forum/post/391</guid><dc:creator><![CDATA[Maxwell]]></dc:creator><pubDate>Thu, 10 Jul 2025 14:42:24 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 14:41:48 GMT]]></title><description><![CDATA[<p dir="auto">Time for everyone to run launchctl list and check for any weird .agent or .helper processes. Better safe than drained</p>
]]></description><link>https://undeads.com/forum/post/390</link><guid isPermaLink="true">https://undeads.com/forum/post/390</guid><dc:creator><![CDATA[alex]]></dc:creator><pubDate>Thu, 10 Jul 2025 14:41:48 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 14:41:24 GMT]]></title><description><![CDATA[<p dir="auto">Over 120 countries? That’s not just targeted — that’s a global campaign. Crypto holders especially need to stay sharp</p>
]]></description><link>https://undeads.com/forum/post/389</link><guid isPermaLink="true">https://undeads.com/forum/post/389</guid><dc:creator><![CDATA[Nahiar806]]></dc:creator><pubDate>Thu, 10 Jul 2025 14:41:24 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 14:39:32 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/smith">@<bdi>Smith</bdi></a><br />
LaunchDaemons, .helper files, remote access… this feels like a movie plot, but it's real life. Stay safe, friends.</p>
]]></description><link>https://undeads.com/forum/post/388</link><guid isPermaLink="true">https://undeads.com/forum/post/388</guid><dc:creator><![CDATA[Sadia Khatun]]></dc:creator><pubDate>Thu, 10 Jul 2025 14:39:32 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 14:38:45 GMT]]></title><description><![CDATA[<p dir="auto">Thank you for posting this. Practical advice and real-world risks explained in a way everyone can understand.</p>
]]></description><link>https://undeads.com/forum/post/387</link><guid isPermaLink="true">https://undeads.com/forum/post/387</guid><dc:creator><![CDATA[Smith]]></dc:creator><pubDate>Thu, 10 Jul 2025 14:38:45 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 14:38:07 GMT]]></title><description><![CDATA[<p dir="auto">These attackers exploiting trust in the freelance community is honestly the worst part. Be careful out there!</p>
]]></description><link>https://undeads.com/forum/post/386</link><guid isPermaLink="true">https://undeads.com/forum/post/386</guid><dc:creator><![CDATA[Dave]]></dc:creator><pubDate>Thu, 10 Jul 2025 14:38:07 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 14:37:31 GMT]]></title><description><![CDATA[<p dir="auto">I checked my system and luckily everything’s clean, but still feeling uneasy about those fake job DMs.</p>
]]></description><link>https://undeads.com/forum/post/385</link><guid isPermaLink="true">https://undeads.com/forum/post/385</guid><dc:creator><![CDATA[Sadia Khatun]]></dc:creator><pubDate>Thu, 10 Jul 2025 14:37:31 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 14:36:41 GMT]]></title><description><![CDATA[<p dir="auto">If AMOS can bypass VMs and sandboxes, even malware analysts are at risk. That’s wild.”</p>
]]></description><link>https://undeads.com/forum/post/384</link><guid isPermaLink="true">https://undeads.com/forum/post/384</guid><dc:creator><![CDATA[rafihasan]]></dc:creator><pubDate>Thu, 10 Jul 2025 14:36:41 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 14:36:05 GMT]]></title><description><![CDATA[<p dir="auto">This is the kind of info that needs to be spread in every crypto community right now.</p>
]]></description><link>https://undeads.com/forum/post/383</link><guid isPermaLink="true">https://undeads.com/forum/post/383</guid><dc:creator><![CDATA[Smith]]></dc:creator><pubDate>Thu, 10 Jul 2025 14:36:05 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 14:35:29 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/smith">@<bdi>Smith</bdi></a><br />
Definitely going to stop downloading cracked apps altogether. Not worth the risk anymore.</p>
]]></description><link>https://undeads.com/forum/post/382</link><guid isPermaLink="true">https://undeads.com/forum/post/382</guid><dc:creator><![CDATA[Dave]]></dc:creator><pubDate>Thu, 10 Jul 2025 14:35:29 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 14:34:56 GMT]]></title><description><![CDATA[<p dir="auto">Crypto and macOS users need to be on high alert. These phishing tactics are getting too real.</p>
]]></description><link>https://undeads.com/forum/post/381</link><guid isPermaLink="true">https://undeads.com/forum/post/381</guid><dc:creator><![CDATA[Sadia Khatun]]></dc:creator><pubDate>Thu, 10 Jul 2025 14:34:56 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 14:33:36 GMT]]></title><description><![CDATA[<p dir="auto">One more reason to stop downloading cracked software. That free plugin might just cost you your wallet</p>
]]></description><link>https://undeads.com/forum/post/380</link><guid isPermaLink="true">https://undeads.com/forum/post/380</guid><dc:creator><![CDATA[rafihasan]]></dc:creator><pubDate>Thu, 10 Jul 2025 14:33:36 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 14:30:21 GMT]]></title><description><![CDATA[<p dir="auto">Freelancers are such easy targets now. If someone sends you a DM about a 'collab' and there's a file attached — assume it’s malicious</p>
]]></description><link>https://undeads.com/forum/post/379</link><guid isPermaLink="true">https://undeads.com/forum/post/379</guid><dc:creator><![CDATA[Maxwell]]></dc:creator><pubDate>Thu, 10 Jul 2025 14:30:21 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 14:29:54 GMT]]></title><description><![CDATA[<p dir="auto">These attackers are getting way too sophisticated. Remote access + persistence = nightmare fuel</p>
]]></description><link>https://undeads.com/forum/post/378</link><guid isPermaLink="true">https://undeads.com/forum/post/378</guid><dc:creator><![CDATA[alex]]></dc:creator><pubDate>Thu, 10 Jul 2025 14:29:54 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 14:29:31 GMT]]></title><description><![CDATA[<p dir="auto">LaunchDaemons are no joke — once malware gets in there with root privileges, it’s game over. Everyone on macOS should audit theirs ASAP.</p>
]]></description><link>https://undeads.com/forum/post/376</link><guid isPermaLink="true">https://undeads.com/forum/post/376</guid><dc:creator><![CDATA[Nahiar806]]></dc:creator><pubDate>Thu, 10 Jul 2025 14:29:31 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 13:46:06 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/smith">@<bdi>Smith</bdi></a><br />
Big thanks to researchers like g0njxa who help us understand threats like this.</p>
]]></description><link>https://undeads.com/forum/post/351</link><guid isPermaLink="true">https://undeads.com/forum/post/351</guid><dc:creator><![CDATA[Sadia Khatun]]></dc:creator><pubDate>Thu, 10 Jul 2025 13:46:06 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 13:38:57 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/dave">@<bdi>Dave</bdi></a><br />
I wish more people took these warnings seriously. Prevention is much easier than dealing with an infected system.</p>
]]></description><link>https://undeads.com/forum/post/350</link><guid isPermaLink="true">https://undeads.com/forum/post/350</guid><dc:creator><![CDATA[Smith]]></dc:creator><pubDate>Thu, 10 Jul 2025 13:38:57 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 13:37:55 GMT]]></title><description><![CDATA[<p dir="auto">Crazy how malware campaigns have gone global so fast—120+ countries already??</p>
]]></description><link>https://undeads.com/forum/post/349</link><guid isPermaLink="true">https://undeads.com/forum/post/349</guid><dc:creator><![CDATA[Dave]]></dc:creator><pubDate>Thu, 10 Jul 2025 13:37:55 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 13:37:10 GMT]]></title><description><![CDATA[<p dir="auto">Appreciate the reminder to stay vigilant. These attackers are ruthless, and we have to protect ourselves.</p>
]]></description><link>https://undeads.com/forum/post/348</link><guid isPermaLink="true">https://undeads.com/forum/post/348</guid><dc:creator><![CDATA[Sadia Khatun]]></dc:creator><pubDate>Thu, 10 Jul 2025 13:37:10 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 11:36:22 GMT]]></title><description><![CDATA[<p dir="auto">Honestly, this is one of the most useful warnings I’ve seen today. Time to be paranoid for the right reasons.</p>
]]></description><link>https://undeads.com/forum/post/343</link><guid isPermaLink="true">https://undeads.com/forum/post/343</guid><dc:creator><![CDATA[Dave]]></dc:creator><pubDate>Thu, 10 Jul 2025 11:36:22 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 11:35:44 GMT]]></title><description><![CDATA[<p dir="auto">Appreciate this info! It’s crazy how these attackers keep finding new ways to exploit users, especially in the crypto space.</p>
]]></description><link>https://undeads.com/forum/post/342</link><guid isPermaLink="true">https://undeads.com/forum/post/342</guid><dc:creator><![CDATA[Smith]]></dc:creator><pubDate>Thu, 10 Jul 2025 11:35:44 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 11:35:06 GMT]]></title><description><![CDATA[<p dir="auto">Wow, this AMOS update is scary. Thanks for the heads-up—really need to double-check my Mac's security settings now.</p>
]]></description><link>https://undeads.com/forum/post/341</link><guid isPermaLink="true">https://undeads.com/forum/post/341</guid><dc:creator><![CDATA[Sadia Khatun]]></dc:creator><pubDate>Thu, 10 Jul 2025 11:35:06 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 11:01:11 GMT]]></title><description><![CDATA[<p dir="auto">Thanks for sharing this important update. It’s scary how these fake job offers are now being used to target freelancers and crypto users. If something feels off, don’t open the file — report and delete it right away. Better to stay safe than sorry!</p>
]]></description><link>https://undeads.com/forum/post/339</link><guid isPermaLink="true">https://undeads.com/forum/post/339</guid><dc:creator><![CDATA[Nayeem Islam]]></dc:creator><pubDate>Thu, 10 Jul 2025 11:01:11 GMT</pubDate></item><item><title><![CDATA[Reply to [WARNING] AMOS Malware Just Got a Major Upgrade – Now With Full Remote Access Capabilities on Thu, 10 Jul 2025 10:53:00 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/lingriiddd">@<bdi>lingriiddd</bdi></a> Auditing LaunchDaemons and checking for suspicious .helper or .agent files is a must right now. The fact that AMOS can bypass sandbox detection shows how advanced it’s become. Mac users really need to stay extra cautious these days</p>
]]></description><link>https://undeads.com/forum/post/338</link><guid isPermaLink="true">https://undeads.com/forum/post/338</guid><dc:creator><![CDATA[MD SANI]]></dc:creator><pubDate>Thu, 10 Jul 2025 10:53:00 GMT</pubDate></item></channel></rss>