COOKIE SPIDER is a cybercriminal group that emerged in June 2025, operating a Malware-as-a-Service (MaaS) platform to distribute SHAMOS, a variant of the Atomic macOS Stealer (AMOS). This group specifically targets macOS users through malvertising campaigns, luring them to fraudulent websites to steal sensitive information and cryptocurrency assets. Its operations are notable for deliberately avoiding victims in Russia and Commonwealth of Independent States (CIS) countries, a practice attributed to adherence to regulations within certain Eastern European cybercriminal forums where the group likely operates. COOKIE SPIDER distinguishes itself by focusing exclusively on macOS users with high-volume, opportunistic campaigns that leverage social engineering and technical evasion to bypass native macOS security features.