Weaponized DMG Files Deliver macOS Infostealer Malware
ID: 68472722-e5b7-5cfa-b7bc-0b6e4f857505
STIX ID: report--68472722-e5b7-5cfa-b7bc-0b6e4f857505
Feed Name: GBHackers
A surge in macOS infostealer campaigns is using convincing, weaponized .dmg installers and social-engineering (e.g., background images, misleading filenames, and instructions to bypass Gatekeeper) distributed via SEO-poisoned results, torrent sites, and cracked-software forums; these installers execute immediately to collect high-value secrets (credentials, cookies, tokens, crypto wallets) and exfiltrate to C2 without persistence. Defenders are advised to monitor macOS mount events (Endpoint Security API), inspect .background artwork (OCR), scan filenames for deceptive patterns, unmount suspicious volumes, terminate related processes, and correlate mount-time telemetry with network and endpoint traces to contain and remediate infections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
