DigitStealer: a JXA-based infostealer that leaves little footprint
ID: 83dc301d-6011-51b3-b516-11d32113a4f1
STIX ID: report--83dc301d-6011-51b3-b516-11d32113a4f1
Feed Name: Jamf Blog
Threat Score
Jamf Threat Labs dissects "DigitStealer", a sophisticated multi-stage macOS infostealer delivered via malicious DMGs and a "drag into Terminal" dropper; it performs locale and Apple Silicon (M2+) hardware checks to avoid analysis, executes AppleScript/JXA stages to harvest browser and wallet data, modifies Ledger Live to redirect wallet traffic, and establishes persistent backdoor polling to attacker C2; the report includes extensive IoCs (hashes, filenames, URLs, domains).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
