New macOS Infinity Stealer uses Nuitka Python payload and ClickFix
ID: 3cf97544-9868-5982-a15a-9b1a818c1612
STIX ID: report--3cf97544-9868-5982-a15a-9b1a818c1612
Feed Name: Security Affairs
Infinity Stealer is a newly observed macOS infostealer campaign that leverages fake Cloudflare CAPTCHA pages (ClickFix) to coerce victims into pasting Terminal commands. The attack chain uses a Bash dropper, a Nuitka-compiled loader and a Python 3.11 stealer to collect browser credentials, Keychain data, crypto wallets, .env files and screenshots, exfiltrating via HTTP and notifying operators via Telegram; Malwarebytes published the analysis and included IOCs and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
