Connect with us

Technology

Over 2,800 websites used to spread AMOS malware

Published

on

Over 2,800 websites used to spread AMOS malware

Ransomware gangs once thrived on infected email attachments and bogus invoices, but security-savvy users and hardened mail gateways have weakened those tactics. Attackers are now focusing on a subtler trick that targets the small checkbox labeled “I’m not a robot” that most people click without thinking. 

A widespread campaign known as MacReaper has compromised more than 2,800 legitimate websites and redirects visitors to an infection process designed specifically for Apple computers. The operation relies on visual trust signals, including a convincing fake of Google’s reCAPTCHA, along with hidden clipboard code that ends with the installation of Atomic macOS Stealer malware, a data-harvesting infostealer distributed through Telegram.

Join the FREE “CyberGuy Report”: Get my expert tech tips, critical security alerts and exclusive deals, plus instant access to my free “Ultimate Scam Survival Guide” when you sign up!

A woman working on her laptop (Kurt “CyberGuy” Knutsson)

How does the attack unfold?

When a Mac user visits one of the compromised websites, they don’t see the page they were expecting. Instead, the site displays a full-screen imitation of Google’s familiar reCAPTCHA box.

Advertisement

This fake reCAPTCHA appears harmless, simply asking the user to click “I’m not a robot.” However, when the user clicks the box, a hidden command is silently copied to their clipboard. Immediately afterward, the page displays a friendly message, complete with familiar macOS keyboard shortcut visuals, explicitly instructing the user to open Terminal and paste what they’ve just copied. If the user follows these instructions, the command downloads and runs the malicious file known as Atomic macOS Stealer (AMOS).

This trick is specifically targeted at Mac users. The website checks the visitor’s operating system and only activates the attack if it detects macOS. For Windows or Linux users, the site behaves normally. Researchers have dubbed this infection method “ClickFix,” referencing the single click that initiates the attack chain.

At the center of this campaign is AMOS, a sophisticated piece of malware that has become notorious in cybercrime circles. AMOS is available for rent on Telegram, with some versions costing attackers up to $3,000 per month. Once installed, AMOS can steal a wide array of sensitive data: it can extract Wi-Fi and app passwords stored in Keychain, collect browser cookies and autofill data, list system information and scan through personal folders such as Desktop and Documents. It is also capable of identifying and targeting more than 50 types of cryptocurrency wallets.

Fake reCAPTCHA (Cyber Security News) (Kurt “CyberGuy” Knutsson)

THE HIDDEN COSTS OF FREE APPS: YOUR PERSONAL INFORMATION

Advertisement

Macs aren’t as secure as Apple wants you to believe

MacReaper challenges two widely held beliefs. The first is that everyday CAPTCHA checks are just harmless speed bumps. The second is that macOS provides a level of built-in security that keeps most attackers at bay. In reality, a single click can expose Keychain credentials, active browser sessions and cryptocurrency wallets.

These are exactly the kinds of targets that attract credential-stuffing groups and profit-driven cybercriminals. Because the attack is triggered by the user, many network monitoring tools treat the traffic as normal, leaving security teams with little to investigate. In environments where Macs and Windows machines share identity systems, one compromised Mac can open access to single sign-on portals, cloud storage and even production codebases.

A woman working on her laptop (Kurt “CyberGuy” Knutsson)

SPOTIFY PLAYLISTS ARE BEING HIJACKED TO PROMOTE PIRATED SOFTWARE AND SCAMS

6 ways you can stay safe from MacReaper attack

To protect yourself from the evolving threat of the MacReaper attack, which continues to target users through sophisticated social engineering tactics, consider implementing these six essential security measures.

Advertisement

1) Be skeptical of CAPTCHA prompts: Legitimate CAPTCHA tests never require you to copy commands or paste anything into Terminal. If a website instructs you to do this, it’s likely a scam. Close the page immediately and avoid interacting with it.

2) Don’t click links from unverified emails and use strong antivirus software: Many MacReaper attacks start with phishing emails that impersonate trusted services. Always verify the sender before clicking on links. If an email seems urgent or unexpected, go directly to the company’s official website instead of clicking any links inside the email.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe. Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices.

3) Enable two-factor authentication: Enable two-factor authentication whenever possible. This adds an extra layer of security by requiring a second form of verification, such as a code sent to your phone, in addition to your password.

4) Keep devices updated: Regularly updating your operating system, browser and security software ensures you have the latest patches against known vulnerabilities. Cybercriminals exploit outdated systems, so enabling automatic updates is a simple but effective way to stay protected.

Advertisement

5) Monitor your accounts for suspicious activity and change your passwords: If you’ve interacted with a suspicious website, phishing email or fake login page, check your online accounts for any unusual activity. Look for unexpected login attempts, unauthorized password resets or financial transactions that you don’t recognize. If anything seems off, change your passwords immediately and report the activity to the relevant service provider. Also, consider using a password manager to generate and store complex passwords. Get more details about my best expert-reviewed password managers of 2025 here.

6) Invest in a personal data removal service: Consider using a service that monitors your personal information and alerts you to potential breaches or unauthorized use of your data. These services can provide early warning signs of identity theft or other malicious activities resulting from MacReaper or similar attacks. While no service promises to remove all your data from the internet, having a removal service is great if you want to constantly monitor and automate the process of removing your information from hundreds of sites continuously over a longer period of time. Check out my top picks for data removal services here.

MASSIVE SECURITY FLAW PUTS MOST POPULAR BROWSERS AT RISK ON MAC

Kurt’s key takeaway

MacReaper makes it clear that the most durable exploits aren’t zero-days but borrowed moments of trust, an authentic-looking CAPTCHA, a helpful-sounding fix, a clipboard that does what it’s told. As Apple tightens the technical screws with Rapid Security Responses and notarization, expect adversaries to double down on such psychological levers. The counter-strategy is to hard-bake healthy skepticism into user behavior and to instrument Macs with the same telemetry layers enterprises already expect from Windows. Security, in other words, has finally become a platform-agnostic muscle, and complacency is the riskiest operating system of all.

Do you think tech companies are doing enough to stop malware like MacReaper? Let us know by writing us at Cyberguy.com/Contact.

Advertisement

For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.

Ask Kurt a question or let us know what stories you’d like us to cover.

Follow Kurt on his social channels:

Answers to the most-asked CyberGuy questions:

New from Kurt:

Advertisement

Copyright 2025 CyberGuy.com. All rights reserved.

Technology

Roland’s Go:Mixer Studio turns your phone into a mobile music studio

Published

on

Roland’s Go:Mixer Studio turns your phone into a mobile music studio

Roland now offers a more capable audio mixer for phones and tablets with the launch of the Go:Mixer Studio. The Go:Mixer audio interface lineup has always been a bit limited, better suited for scrappy live streams and capturing quick demos on their phones than professional recording. The Go:Mixer Studio is an attempt to actually reach that lofty goal, with more inputs and outputs, built-in effects, and up to 24-bit / 192kHz audio. There’s even an iOS app that allows you to capture video and multitrack audio simultaneously.

Streaming and social video are still the major use cases here. The Go:Mixer Studio can even be mounted on a mic stand so you can keep it in easy reach during a live session. The screen and knobs allow you to control all the parameters on the Go:Mixer Studio directly, but there’s also a desktop app for Windows and MacOS that gives you complete control of the mixer remotely.

There’s plenty of connectivity, including two XLR inputs on the back with phantom power, a 1/4-inch instrument input for directly connecting a guitar or bass, stereo 1/4-inch line-in jacks, and an aux input. There’s also 1/8-inch TRS MIDI in and out, two headphone jacks, and stereo line outs for connecting to studio monitors. Each audio input has a dedicated EQ and compressor on the channel. The XLR and instrument ins also have reverb available.

The Go:Mixer Studio is available now for $299.

Continue Reading

Technology

Alexa.com brings Alexa+ to your browser

Published

on

Alexa.com brings Alexa+ to your browser

NEWYou can now listen to Fox News articles!

For years, Alexa mostly stayed in one place. It lived on kitchen counters, nightstands or living room shelves. That setup worked for music and timers, but it also limited when and how people could actually use the assistant. Now that is changing.

Amazon has rolled out Alexa.com, which brings Alexa+ directly to your web browser for Early Access users. Instead of relying on a speaker or phone, you can now open a laptop and start using Alexa like any other web-based AI tool.

This shift is less about new tricks and more about access. Alexa can now follow you throughout your day instead of waiting for you at home.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Advertisement

CHATGPT HEALTH PROMISES PRIVACY FOR HEALTH CONVERSATIONS

Amazon’s Alexa is no longer tied to a smart speaker, with Alexa.com bringing the assistant and Alexa+ directly to the web browser for Early Access users. (Photo Illustration by Thomas Fuller/SOPA Images/LightRocket via Getty Images)

What Alexa.com actually is

Alexa.com is the browser-based version of Alexa+. You can type questions, explore topics, plan trips, organize tasks, or create content without touching a smart speaker. The biggest difference is continuity. Alexa keeps context across devices, so conversations carry over whether you are on your laptop, phone, Echo, or Fire TV. You do not have to repeat yourself every time you switch screens. That makes Alexa feel less like a command tool and more like an assistant that remembers what you are working on.

Who can use Alexa.com right now

Alexa.com is not open to everyone yet. To use it, you need:

  • Alexa+ Early Access
  • An Amazon account linked to a compatible Echo, Fire TV, or Fire tablet
  • US-based Amazon account
  • Device language set to English, United States

Child profiles are not supported on the browser version. Older Echo devices will continue using the original Alexa.

What Alexa.com cannot do yet

Because Alexa.com is still in Early Access, it has limits that matter for everyday users. Right now:

Advertisement
  • You can only type to Alexa in your browser
  • Voice interaction is not supported on the web
  • Music playback is not available
  • Smart home controls are limited compared to Echo devices

Amazon says features will roll out gradually. Alexa.com is meant to complement your devices, not fully replace them yet.

Meal planning without juggling tabs

One area where Alexa.com feels genuinely useful is meal planning. You can ask Alexa for a full week of meals and set preferences like high protein, low sugar, or kid-friendly lunches. Alexa generates a plan and turns it into a shopping list. From there, items can be added directly to Amazon Fresh or Whole Foods. Instead of bouncing between recipes, notes and carts, everything happens in one place.

Organizing everyday life in one place

Alexa.com also works as a lightweight life organizer. You can upload documents, emails and images so Alexa can pull out key details. That includes appointments, reminders and schedules you would otherwise forget. Instead of searching your inbox, you can ask Alexa when the dog last went to the vet or what time practice starts tonight. The information stays available across devices.

Smart home access, with limits

Alexa.com keeps your smart home controls visible next to your chat window. While full smart home control is still limited in the browser, Alexa.com lets you check status, review activity and continue actions on your Echo or Fire TV devices. It is most useful as a bridge. You can start something in the browser and finish it at home without starting over.

Recipes that follow you into the kitchen

Alexa.com also simplifies cooking. If you find a recipe online, you can paste the link into Alexa and ask it to adjust for dietary needs. Alexa can save it, convert it into ingredients and add everything to your shopping list. When it is time to cook, Alexa can pull the recipe up on your Echo Show, guide you step by step and manage timers so your hands stay free.

5 TECH TERMS THAT SHAPE YOUR ONLINE PRIVACY

Advertisement

Alexa.com lets users type questions, plan trips, organize tasks and create content without relying on an Echo or smartphone. (Michael Nagle/Bloomberg via Getty Images)

Finding something to watch faster

Decision fatigue hits hard at night. On Alexa.com, you can explore movie themes, get recommendations and save picks for later. When you sit down, Alexa remembers your choices and sends them to your Fire TV. That cuts down on scrolling and family debates.

What about privacy

Using Alexa on the web raises natural privacy questions. Amazon says Alexa+ includes built-in protections and user controls. Still, it is worth taking a minute to review your settings, especially if you plan to upload documents or personal information. A few smart habits can help:

  • Check your Alexa privacy settings and review stored activity
  • Avoid uploading sensitive documents like IDs or medical records
  • Use strong antivirus software to protect your device. The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.

As with any AI assistant, convenience comes with trade-offs. Staying aware helps you stay in control.

How much Alexa+ will cost

Alexa+ is free during Early Access. When Early Access ends, you will not be automatically charged. After that:

  • Alexa+ stays free with a Prime membership
  • Non-Prime users can subscribe for $19.99 per month

This makes Alexa.com more appealing for Prime members and a tougher sell for everyone else.

What this means to you

For most people, Alexa.com is about convenience. If you already use Alexa at home, the web version makes it easier to use during the day. You can plan, organize or look things up from your computer and then pick up later on your phone or Echo. It also puts Alexa in the same category as other browser-based AI tools, but with deeper ties to shopping, smart home features and entertainment. Whether you stick with it will likely come down to how often you want Alexa to help you during your day.

Advertisement

Take my quiz: How safe is your online security?

Think your devices and data are truly protected? Take this quick quiz to see where your digital habits stand. From passwords to Wi-Fi settings, you’ll get a personalized breakdown of what you’re doing right and what needs improvement. Take my Quiz here: Cyberguy.com.

YOU CAN FINALLY CHANGE YOUR GMAIL ADDRESS WITHOUT LOSING DATA

Amazon says Alexa.com allows conversations to carry over across devices, giving users continuity between laptops, phones and smart home screens. (Photographer: Michael Nagle/Bloomberg via Getty Images)

Kurt’s key takeaways

Alexa.com does not reinvent Alexa. It simply makes it easier to use where people already spend time. By bringing Alexa+ to the browser, Amazon is betting that continuity matters more than novelty. For some users, that will be enough to make Alexa feel relevant again.

Advertisement

If Alexa followed you from your laptop to your living room, would you actually rely on it more, or would it still feel optional? Let us know by writing to us at Cyberguy.com.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Copyright 2026 CyberGuy.com.  All rights reserved.

Advertisement
Continue Reading

Technology

A second US Sphere could come to Maryland

Published

on

A second US Sphere could come to Maryland

The second US sphere would be built in an area known as National Harbor in Prince George’s County, Maryland. Located along the Potomac River, National Harbor currently features a convention center, multiple hotels, restaurants, and shops. While Abu Dhabi plans to build a sphere as large as the one in Las Vegas, the National Harbor venue would be one of the first mini-Sphere venues announced last March.

Its capacity would be limited to 6,000 seats instead of over 17,000. But the smaller Sphere would still be hard to miss with an exterior LED exosphere for showcasing the “artistic and branded content” that helped make the original sphere a unique part of the Las Vegas skyline.

The inside of the mini-Sphere will feature a high-resolution 16,000 by 16,000 pixel wrap-around screen, the company’s immersive sound technology, haptic seating, and “4D environmental effects.” For the AI-enhanced version of The Wizard of Oz currently playing in Las Vegas, audiences experience effects like wind, fog, smells, and apples falling from the ceiling.

The mini-Sphere will potentially also be cheaper to build than the $2.3 billion original, but its construction is contingent on the “receipt of certain governmental incentives and approvals from Prince George’s County and the State of Maryland.” Sphere Entertainment says the project “would utilize a combination of public and private funding, including approximately $200 million in state, local, and private incentives,” but would potentially generate millions of dollars in revenue for the country and state while supporting over 4,700 jobs once it opens.

Continue Reading
Advertisement

Trending