Mac users warned about new DigitStealer information stealer
ID: cfbabe24-db43-56c9-83e6-c815a391b9b2
STIX ID: report--cfbabe24-db43-56c9-83e6-c815a391b9b2
Feed Name: Malwarebytes Blog
DigitStealer is a macOS-targeting infostealer delivered via a fake “DynamicLake” installer that tricks users into running Terminal commands; it favors newer ARM (M2+) Macs, performs region and VM checks to evade analysis, and uses a largely fileless, multi-stage chain to exfiltrate documents, browser data, keychain passwords, crypto wallets, VPN configurations (OpenVPN, Tunnelblick) and Telegram sessions. Recommended protections include avoiding unsolicited Terminal commands, downloading apps only from trusted sources, keeping OS and security software updated, and enabling multi-factor authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
