logo

DigitStealer: a JXA-based infostealer that leaves little footprint

ID: 83dc301d-6011-51b3-b516-11d32113a4f1

STIX ID: report--83dc301d-6011-51b3-b516-11d32113a4f1

Feed Name: Jamf Blog

Threat Score
75/100

Date Published: 2025-11-13

Date Updated: 2026-07-16

...
...

Jamf Threat Labs dissects "DigitStealer", a sophisticated multi-stage macOS infostealer delivered via malicious DMGs and a "drag into Terminal" dropper; it performs locale and Apple Silicon (M2+) hardware checks to avoid analysis, executes AppleScript/JXA stages to harvest browser and wallet data, modifies Ledger Live to redirect wallet traffic, and establishes persistent backdoor polling to attacker C2; the report includes extensive IoCs (hashes, filenames, URLs, domains).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.