logo

Fake Cloudflare CAPTCHA Pages Spread Infiniti Stealer Malware on macOS Systems

ID: 7d42dee8-ced5-53ac-85e7-773f6ca6da93

STIX ID: report--7d42dee8-ced5-53ac-85e7-773f6ca6da93

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-27

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Infiniti Stealer is a macOS-focused infostealer campaign that uses fraudulent Cloudflare verification pages and a ClickFix social-engineering trick to get users to run a Terminal command, initiating a three-stage infection: a Bash dropper, a Nuitka-compiled Mach-O loader, and a final Nuitka-compiled Python stealer (UpdateHelper.bin). The stealer harvests Chromium/Firefox credentials, macOS Keychain entries, cryptocurrency wallets, screenshots, and developer secrets, exfiltrates data via HTTP POST, and notifies the operator via Telegram; it includes sandbox-evasion checks and randomized delays to avoid detection. Recommended immediate actions include stopping sensitive device use, changing passwords from a clean device, revoking sessions and tokens, searching /tmp and ~/Library/LaunchAgents/, and running a full security scan.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.