<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Amos on CuraSec</title><link>https://curasec.metacog.co.kr/tags/amos/</link><description>Recent content in Amos on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 03 Aug 2026 13:48:19 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/amos/index.xml" rel="self" type="application/rss+xml"/><item><title>SANS ISC: Atomic macOS (AMOS) Stealer Infection Analysis</title><link>https://curasec.metacog.co.kr/insights/2026-08-03-atomic-macos-amos-stealer-infection-sun-aug-2nd/</link><pubDate>Mon, 03 Aug 2026 13:48:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-03-atomic-macos-amos-stealer-infection-sun-aug-2nd/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> AMOS is an active macOS infostealer targeting credentials and sensitive files; the summary is too thin to confirm specifics, so read the full SANS ISC diary for infection chain details and any affected software or configuration indicators relevant to your macOS fleet.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> AMOS campaigns continue to hit macOS endpoints — review the full SANS ISC diary entry for IOCs and TTPs to build or tune macOS-targeted detections in your EDR and SIEM, particularly around credential-harvesting process behavior.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>