According to Moonlock, a cybersecurity company, the AMOS malware, which targets MacBook users, can now clone Ledger Live software and may soon be able to clone other wallet applications.
New Capabilities of AMOS
The malware known as "Atomic MacOS" or "AMOS" has developed new capabilities that allow it to clone wallet applications and steal cryptocurrency from users.
According to an August 5 report from Moonlock Lab, a cybersecurity company, the program is making a resurgence. The company found that it is being advertised through Google AdSense.
Spread of AMOS
In these ads, the malware disguises itself as popular macOS programs, including the screen-sharing app Loom, UI design tool Figma, VPN Tunnelblick, and instant messaging app Callzy. However, the developers of these apps have not authorized the creation of these fake AMOS malware versions.
When users click on the Google AdSense ads, they are led to smokecoffeeshop.com, which then redirects them to a fake Loom website.
The fake website looks identical to the real one. However, when users click the "Get Loom for free" button, instead of downloading the legitimate Loom program, they download the "AMOS malware."

History of AMOS
AMOS is not a new program. Cybersecurity company Cyble reported its existence as early as April 2023. According to Cyble, the program is sold to cybercriminals on Telegram as a subscription service for $1,000 per month.
Moonlock claims to have traced the software to a developer named Crazy Evil, who advertises on Telegram. This group boasts about AMOS's ability to clone Ledger Live.
AMOS Attack Targets
AMOS can attack more than 50 types of crypto wallets, including Electrum, MetaMask, Coinbase, Binance, Exodus, Atomic, Coinomi, and others. When AMOS finds these wallets on a user's computer, it steals the wallet's data. According to Cyble, users' encrypted keyvault files are likely stolen by AMOS.
If the keyvault file is stolen, attackers can drain funds from the user's wallet, especially if the victim used a weak password when first creating the wallet account.

AMOS targets wallets. Source: Cyble Research and Intelligence Labs
New App Cloning Capabilities
Moonlock claims that the software has been upgraded, as Moonlock found a new version capable of replacing specific crypto wallet apps with clones and easily deleting the victim's original wallet.
Specifically, it can clone the Ledger Live software. Moonlock emphasizes that this capability "has never been reported in previous versions of AMOS and its current ability represents a significant advancement for AMOS."
Impact on Ledger Users
Ledger devices store private keys in a hardware wallet, which is beyond the reach of malware installed on a computer. Users must also confirm each transaction on the hardware wallet, making it difficult for malware to steal crypto from Ledger users.
However, the attacker's intent in cloning Ledger Live might be to display deceptive information on the user's screen, leading the user to send crypto to the attacker's address.
Future Risks
Even more concerning than the ability to clone Ledger Live is the report that future versions of the software may be able to clone other apps. This could include software wallets like MetaMask and Trust Wallet. "If the new version of AMOS can replace Ledger Live with a cloned fake app, it could do the same with other apps."
Software wallets display all information directly on the computer screen, making deceptive displays even more dangerous.
Warning for Mac Users
Users who use crypto wallet software on Mac should be aware that AMOS specifically targets MacBook users. This malware often spreads through Google AdSense ads, so extreme caution is advised when downloading software from websites found through banners or advertisements. It might appear to be Loom, Callzy, or other popular programs, but in reality, it's AMOS malware.
Other Threats to Crypto Users
Malware continues to be a serious threat to crypto users. In addition to AMOS, other malware also targets cryptocurrency users.
"Stealer" Programs Using "Clipping"
On August 16, cybersecurity company Check Point Research discovered a similar "stealer" program that siphons crypto through a method called "clipping." This method can involve interfering with data copied to the clipboard, potentially allowing important user data to be stolen unknowingly.
"Durian" Malware Attacking Crypto Exchanges
On May 13, Kaspersky Labs discovered malware named "Durian," which was used to attack cryptocurrency exchanges. This malware may aim to breach exchange systems, potentially affecting a large number of users.
Conclusion
The threat of malware to cryptocurrency users remains a serious and ongoing problem. Not only AMOS, but other malware also constantly develops new attack methods. Crypto users should increase their self-protection, including regularly updating security software, using strong passwords, and exercising extreme caution when conducting online cryptocurrency transactions.
References
Mac users beware: AMOS malware clones wallet apps and comes for your crypto







แชร์:
How can Bitcoin be lost?
Can I recover a lost seed phrase?