logo

Fake Cloudflare CAPTCHA Pages Deliver Infiniti Stealer Malware on macOS

ID: 674b82cc-ac24-5871-b002-5214f7d2d11d

STIX ID: report--674b82cc-ac24-5871-b002-5214f7d2d11d

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-03-27

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Infiniti Stealer is an actively distributed macOS infostealer delivered through fake Cloudflare-style CAPTCHA pages that coerce users to paste and run Terminal commands (ClickFix). The campaign uses a three-stage chain—a Bash dropper, a Nuitka-compiled Mach-O loader, and a Python-based stealer—to harvest browser credentials, Keychain items, crypto wallets, developer secrets, and screenshots, exfiltrating data via HTTP and notifying operators via Telegram; the report includes hashes, domains/URLs, file paths, detection-evasion notes, and recommended remediation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.