logo

Infostealer Campaigns Expand to macOS as Attackers Abuse Python and Trusted Platforms

ID: bbf7131b-bff7-53ac-8d67-64b875089934

STIX ID: report--bbf7131b-bff7-53ac-8d67-64b875089934

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-03

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Infostealer activity that historically targeted Windows is increasingly targeting macOS through both native macOS families (e.g., DigitStealer, MacSync, AMOS) and cross-platform Python stealers. Attackers use malvertising, spoofed download pages, fake apps, and social engineering (including copy-paste Terminal commands) to deploy payloads that leverage built-in utilities and scripting to harvest browser passwords, macOS Keychain data, crypto wallets, and cloud/source-code credentials, then exfiltrate data to attacker-controlled infrastructure — posing elevated risk to consumers and organizations, including potential downstream supply-chain compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.