Fake Cloudflare CAPTCHA Pages Spread Infiniti Stealer Malware on macOS Systems
ID: 7d42dee8-ced5-53ac-85e7-773f6ca6da93
STIX ID: report--7d42dee8-ced5-53ac-85e7-773f6ca6da93
Feed Name: cybersecurityNews.com
Infiniti Stealer is a macOS-focused infostealer campaign that uses fraudulent Cloudflare verification pages and a ClickFix social-engineering trick to get users to run a Terminal command, initiating a three-stage infection: a Bash dropper, a Nuitka-compiled Mach-O loader, and a final Nuitka-compiled Python stealer (UpdateHelper.bin). The stealer harvests Chromium/Firefox credentials, macOS Keychain entries, cryptocurrency wallets, screenshots, and developer secrets, exfiltrates data via HTTP POST, and notifies the operator via Telegram; it includes sandbox-evasion checks and randomized delays to avoid detection. Recommended immediate actions include stopping sensitive device use, changing passwords from a clean device, revoking sessions and tokens, searching /tmp and ~/Library/LaunchAgents/, and running a full security scan.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
