logo

Weaponized DMG Files Deliver macOS Infostealer Malware

ID: 68472722-e5b7-5cfa-b7bc-0b6e4f857505

STIX ID: report--68472722-e5b7-5cfa-b7bc-0b6e4f857505

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

Author: Mayura Kathir

...
...

A surge in macOS infostealer campaigns is using convincing, weaponized .dmg installers and social-engineering (e.g., background images, misleading filenames, and instructions to bypass Gatekeeper) distributed via SEO-poisoned results, torrent sites, and cracked-software forums; these installers execute immediately to collect high-value secrets (credentials, cookies, tokens, crypto wallets) and exfiltrate to C2 without persistence. Defenders are advised to monitor macOS mount events (Endpoint Security API), inspect .background artwork (OCR), scan filenames for deceptive patterns, unmount suspicious volumes, terminate related processes, and correlate mount-time telemetry with network and endpoint traces to contain and remediate infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.