logo

Infostealer Attacks Hit macOS, Abusing Python and Trusted Platforms

ID: 039622da-aa2f-5437-ab10-15776f90ff5d

STIX ID: report--039622da-aa2f-5437-ab10-15776f90ff5d

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-02-03

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

The report describes a spike in macOS- and Windows-focused infostealer campaigns leveraging social engineering, fake installers, malvertising, and Python-based payloads to steal browser credentials, keychain entries, cloud developer keys, and cryptocurrency wallets; it names families (DigitStealer, MacSync, AMOS, PXA, Eternidade), documents delivery mechanisms and evasion techniques (fileless execution, AppleScript/JXA, obfuscated Python, DLL sideloading), and publishes SHA-256 hashes and domains as IOCs while recommending detection and mitigation controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.