logo

Infostealers without borders: macOS, Python stealers, and platform abuse

ID: b9fdc2e4-c5fc-56fb-942f-ef18e3820d52

STIX ID: report--b9fdc2e4-c5fc-56fb-942f-ef18e3820d52

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2026-02-02

Date Updated: 2026-04-28

Author: Microsoft Defender Security Research Team

...
...

This Microsoft Defender Experts blog details active and evolving infostealer campaigns (macOS-centric stealers like DigitStealer, MacSync, AMOS; Python-based PXA stealer; Eternidade via WhatsApp; and a malicious Crystal PDF installer) that employ social engineering, fileless execution, living-off-the-land, obfuscated Python, DLL sideloading, and platform abuse to harvest browser credentials, wallets, cloud and developer secrets. The report includes mitigation guidance, Defender XDR detections, hunting queries, and extensive IoCs (hashes, domains, URLs, IPs) to support detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.