Fake Cloudflare CAPTCHA Pages Deliver Infiniti Stealer Malware on macOS
ID: 674b82cc-ac24-5871-b002-5214f7d2d11d
STIX ID: report--674b82cc-ac24-5871-b002-5214f7d2d11d
Feed Name: GBHackers
Infiniti Stealer is an actively distributed macOS infostealer delivered through fake Cloudflare-style CAPTCHA pages that coerce users to paste and run Terminal commands (ClickFix). The campaign uses a three-stage chain—a Bash dropper, a Nuitka-compiled Mach-O loader, and a Python-based stealer—to harvest browser credentials, Keychain items, crypto wallets, developer secrets, and screenshots, exfiltrating data via HTTP and notifying operators via Telegram; the report includes hashes, domains/URLs, file paths, detection-evasion notes, and recommended remediation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
