logo

Mac users warned about new DigitStealer information stealer

ID: cfbabe24-db43-56c9-83e6-c815a391b9b2

STIX ID: report--cfbabe24-db43-56c9-83e6-c815a391b9b2

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2025-11-19

Date Updated: 2026-04-28

...
...

DigitStealer is a macOS-targeting infostealer delivered via a fake “DynamicLake” installer that tricks users into running Terminal commands; it favors newer ARM (M2+) Macs, performs region and VM checks to evade analysis, and uses a largely fileless, multi-stage chain to exfiltrate documents, browser data, keychain passwords, crypto wallets, VPN configurations (OpenVPN, Tunnelblick) and Telegram sessions. Recommended protections include avoiding unsolicited Terminal commands, downloading apps only from trusted sources, keeping OS and security software updated, and enabling multi-factor authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.