Fake Google Chrome, Safari Updates Infecting Mac Computers With AMOS Malware

Malware creators are using hijacked Wordpress websites to convince users to download fake Google Chrome and Safari updates that are infected with AMOS malware.

Advertisement
Written by David Delima | Updated: 22 November 2023 18:31 IST
Highlights
  • AMOS malware is targeting macOS users using social engineering
  • The malware is installed under the guise of a browser update
  • Hijacked sites trick users into downloading fake Safari, Chrome updates

Chrome and Safari users must keep an eye on websites prompting to install browser updates

Photo Credit: Unsplash/ @firmbee

Fake Google Chrome and Safari updates for macOS are being used to infect Mac computers with the nefarious Atomic Stealer malware, also known as AMOS. Distributed to Mac owners as part of a social engineering campaign, AMOS can steal passwords, private files stored on a Mac. Users will need to stay alert and possibly use web protection tools in order to protect themselves from malware distributed by social engineering, as malware creators appear to be turning their attention to Mac owners.

Security firm Malwarebytes shared details of the latest version of Atomic Stealer, malware that is distributed to macOS users via ClearFake, a campaign that uses hijacked WordPress websites to deliver fake browser updates for Chrome and Safari. The distribution of AMOS via ClearFake to macOS users was recently spotted by Ankit Anubhav, a security researcher.

Advertisement

The fake Google Chrome update page shown to users
Photo Credit: Malwarebytes

Advertisement

 

The malware is distributed via hijacked sites that closely resemble the Google Chrome download page, and a fake Safari update page that uses outdated icons from older macOS versions. However, the rest of the webpage design might convince some users to click and download the malware, while the fake Chrome download looks more convincing.

Advertisement

When the user clicks the download button, the malicious .dmg file is then downloaded to the Mac computer, disguised as a browser installer. Once it downloaded and opened, the user is prompted to enter the administrator password that will run nefarious commands on the device, including stealing passwords from Apple's Keychain and exfiltrate document, images, wallets and other data from the user's desktop and documents folders on macOS.

In order to stay protected from the malware, users will have to make sure they use some form of web protection — such as the Safe Browsing setting inside Google Chrome. Doing so might block some of these malicious sites from loading altogether.

Advertisement

Meanwhile, users should avoid downloading installers for Chrome from unknown websites. These social engineering websites are aimed at fooling users who might find it difficult to discern which websites are genuine. A good rule of thumb is to check whether the address bar shows google.com. On the other hand, Apple does not distribute Safari updates outside of operating system updates, so there are no official downloads that can be installed by users.


Is the Samsung Galaxy Z Flip 5 the best foldable phone you can buy in India right now? We discuss the company's new clamshell-style foldable handset on the latest episode of Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Motorola Edge 70 Pro Arrives With a 6,500mAh Battery at This Price in India
  2. Oppo F33 Pro 5G Review: The Best Looking Phone Under Rs. 40,000?
  3. Vivo X300 Ultra, Vivo X300 FE Will Launch in India on This Date
  4. OnePlus Watch 4 Listing Leaves Little to the Imagination Ahead of Debut
  5. Elden Ring Movie Film Adaptation Release Date, Full Cast Revealed
  1. Qualcomm CEO Reportedly Visits Samsung Foundry in Korea to Discuss Producing 2nm Chips
  2. Coinbase Announces USDC-INR Trading Services for Users in India
  3. Redmi K Pad 2 Launched With 8.8-Inch 3K Display, Dimensity 9500 Chip: Price, Specifications
  4. OnePlus Watch 4 Launch Appears Imminent as Listing Confirms Snapdragon W5 Chip, OxygenOS Watch 8
  5. Sennheiser CX 80U, Sennheiser HD 400U With USB Type-C Connectivity Launched in India: Price, Features
  6. Elden Ring Film Adaptation Sets 2028 Release Date; Full Cast Revealed as Production Begins
  7. Honor 600 Pro and Honor 600 Launched With 7,000mAh Batteries, 200-Megapixel Cameras: Price, Specifications
  8. Scammers Offer Passage to Ships Stranded Near Strait of Hormuz in Exchange for Crypto: Report
  9. Apple's iOS 27, macOS 27 and iPadOS 27 Updates Will Introduce Stricter Network Security Settings
  10. OpenAI Unveils ChatGPT Images 2.0 With Improved Image Generation, Reasoning Capabilities
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.