Microsoft Warns Python Infostealers Target macOS via Fake Ads and Installers
ID: 4657fc6d-cfc1-5bd7-926e-91a06ba4da93
STIX ID: report--4657fc6d-cfc1-5bd7-926e-91a06ba4da93
Feed Name: The Hacker News
Microsoft warns of rapidly expanding infostealer campaigns that now target macOS as well as Windows by leveraging Python-based cross-platform stealers and platform abuse via malvertising (e.g., ClickFix/Google Ads) to deliver fake installers and DMGs. Multiple stealer families (AMOS, MacSync, DigitStealer, PXA Stealer, Eternidade) are observed using fileless techniques, native utilities, AppleScript, and messaging apps/Telegram for C2, enabling theft of credentials, cookies, iCloud Keychain, developer secrets, and financial data; organizations are advised to educate users and monitor suspicious Terminal activity and network egress.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
