Infostealers without borders: macOS, Python stealers, and platform abuse
ID: b9fdc2e4-c5fc-56fb-942f-ef18e3820d52
STIX ID: report--b9fdc2e4-c5fc-56fb-942f-ef18e3820d52
Feed Name: Microsoft Security
Date Published: 2026-02-02
Date Updated: 2026-04-28
Author: Microsoft Defender Security Research Team
This Microsoft Defender Experts blog details active and evolving infostealer campaigns (macOS-centric stealers like DigitStealer, MacSync, AMOS; Python-based PXA stealer; Eternidade via WhatsApp; and a malicious Crystal PDF installer) that employ social engineering, fileless execution, living-off-the-land, obfuscated Python, DLL sideloading, and platform abuse to harvest browser credentials, wallets, cloud and developer secrets. The report includes mitigation guidance, Defender XDR detections, hunting queries, and extensive IoCs (hashes, domains, URLs, IPs) to support detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
