Sophisticated macOS Infostealers Get Past Apple's Built-In Detection
ID: 36b08f43-f022-585d-b48b-a95e555514fa
STIX ID: report--36b08f43-f022-585d-b48b-a95e555514fa
Feed Name: Dark Reading
Date Published: 2024-01-17
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers report that multiple macOS infostealers — KeySteal, Atomic Stealer, and CherryPie — are actively evolving to bypass Apple’s XProtect and other detection systems by using multi-architecture binaries, language rewrites, anti-analysis/VM checks, and clear hardcoded C2s; distribution appears to leverage dmg/pkg installers, torrents, and gaming-focused channels, and the activity underscores a rising trend of macOS-focused credential and wallet theft that requires updated detection and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
