logo

Sophisticated macOS Infostealers Get Past Apple's Built-In Detection

ID: 36b08f43-f022-585d-b48b-a95e555514fa

STIX ID: report--36b08f43-f022-585d-b48b-a95e555514fa

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-01-17

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers report that multiple macOS infostealers — KeySteal, Atomic Stealer, and CherryPie — are actively evolving to bypass Apple’s XProtect and other detection systems by using multi-architecture binaries, language rewrites, anti-analysis/VM checks, and clear hardcoded C2s; distribution appears to leverage dmg/pkg installers, torrents, and gaming-focused channels, and the activity underscores a rising trend of macOS-focused credential and wallet theft that requires updated detection and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.