Home
News
Tech Grid
Data & Analytics
Data Processing Data Management Analytics Data Infrastructure Data Integration & ETL Data Governance & Quality Business Intelligence DataOps Data Lakes & Warehouses Data Quality Data Engineering Big Data
Enterprise Tech
Digital Transformation Enterprise Solutions Collaboration & Communication Low-Code/No-Code Automation IT Compliance & Governance Innovation Enterprise AI Data Management HR
Cybersecurity
Risk & Compliance Data Security Identity & Access Management Application Security Threat Detection & Incident Response Threat Intelligence AI Cloud Security Network Security Endpoint Security Edge AI
AI
Ethical AI Agentic AI Enterprise AI AI Assistants Innovation Generative AI Computer Vision Deep Learning Machine Learning Robotics & Automation LLMs Document Intelligence Business Intelligence Low-Code/No-Code Edge AI Automation NLP AI Cloud
Cloud
Cloud AI Cloud Migration Cloud Security Cloud Native Hybrid & Multicloud Cloud Architecture Edge Computing
IT & Networking
IT Automation Network Monitoring & Management IT Support & Service Management IT Infrastructure & Ops IT Compliance & Governance Hardware & Devices Virtualization End-User Computing Storage & Backup
Human Resource Technology Agentic AI Robotics & Automation Innovation Enterprise AI AI Assistants Enterprise Solutions Generative AI Regulatory & Compliance Network Security Collaboration & Communication Business Intelligence Leadership Artificial Intelligence Cloud
Finance
Insurance Investment Banking Financial Services Security Payments & Wallets Decentralized Finance Blockchain
HR
Talent Acquisition Workforce Management AI HCM HR Cloud Learning & Development Payroll & Benefits HR Analytics HR Automation Employee Experience Employee Wellness
Marketing
AI Customer Engagement Advertising Email Marketing CRM Customer Experience Data Management Sales Content Management Marketing Automation Digital Marketing Supply Chain Management Communications Business Intelligence Digital Experience SEO/SEM Digital Transformation Marketing Cloud Content Marketing E-commerce
Consumer Tech
Smart Home Technology Home Appliances Consumer Health AI
Interviews
Think Stack
Press Releases
Articles
Resources
  • Threat Intelligence

LastPass Uncovers MacOS Cyberattack Distributing Atomic Stealer


LastPass Uncovers MacOS Cyberattack Distributing Atomic Stealer
  • Source: Source Logo
  • |
  • September 22, 2025

LastPass, a leader in password and identity management trusted by over 100,000 businesses worldwide, has uncovered a widespread cyberattack campaign targeting MacOS users. The campaign, detected by the company’s Threat Intelligence, Mitigation, and Escalation (TIME) team, involves fraudulent GitHub repositories impersonating trusted companies, including LastPass itself, to spread the Atomic Stealer (AMOS) malware.

Quick Intel

  • LastPass identifies a cyberattack targeting Mac users via fake GitHub pages.

  • Attackers used SEO manipulation to lure victims into downloading malware.

  • Fraudulent repos impersonated trusted companies, including LastPass.

  • The malware, Atomic Stealer, is designed to steal sensitive information.

  • LastPass swiftly reported and took down the fraudulent GitHub repositories.

  • Indicators of Compromise (IoCs) published to aid wider threat mitigation.

Cyberattack Campaign Uncovered

The attackers created GitHub pages falsely claiming to host legitimate MacOS applications from companies such as LastPass. Through aggressive Search Engine Optimization (SEO) tactics, these malicious repositories appeared prominently in search results on platforms like Google and Bing. Unsuspecting users who clicked the links were redirected to malicious websites instructing them to execute terminal commands, which ultimately installed the Atomic Stealer malware.

Atomic Stealer: A Rising Threat

The Atomic Stealer (AMOS) malware, active since at least April 2023, is linked to financially motivated cybercrime groups. Once deployed, it harvests sensitive data from infected systems, including login credentials and personal information, posing a significant risk to both individuals and organizations.

LastPass Response and Industry Collaboration

“Protecting our users is our highest priority,” said Alex Cox, Director of the Threat Intelligence, Mitigation, and Escalation (TIME) team at LastPass. “We acted swiftly to identify and report the fraudulent GitHub pages impersonating LastPass, which have since been taken down. We continue to monitor this campaign and collaborate with industry partners to disrupt its infrastructure.”

The TIME team acted quickly to remove the fraudulent repositories and continues to track the threat actors behind the campaign. LastPass has shared Indicators of Compromise (IoCs) with the wider security community to help organizations detect and neutralize related attacks.

User Advisory

LastPass urges users to remain cautious and avoid downloading software from unofficial sources. By maintaining vigilance and verifying trusted download channels, users can significantly reduce exposure to malware campaigns like Atomic Stealer.

For more information and ongoing updates, visit the LastPass Labs Blog.

About LastPass

LastPass is a leading identity and password manager, making it easier to log in to life and work. Trusted by 100,000 businesses and millions of users, LastPass combines advanced security with effortless access for individuals, families, small business owners, and enterprise professionals.

  • CybersecurityThreat IntelligenceData ProtectionPassword Management
News Disclaimer
  • Share