logo

Microsoft Warns Python Infostealers Target macOS via Fake Ads and Installers

ID: 4657fc6d-cfc1-5bd7-926e-91a06ba4da93

STIX ID: report--4657fc6d-cfc1-5bd7-926e-91a06ba4da93

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Microsoft warns of rapidly expanding infostealer campaigns that now target macOS as well as Windows by leveraging Python-based cross-platform stealers and platform abuse via malvertising (e.g., ClickFix/Google Ads) to deliver fake installers and DMGs. Multiple stealer families (AMOS, MacSync, DigitStealer, PXA Stealer, Eternidade) are observed using fileless techniques, native utilities, AppleScript, and messaging apps/Telegram for C2, enabling theft of credentials, cookies, iCloud Keychain, developer secrets, and financial data; organizations are advised to educate users and monitor suspicious Terminal activity and network egress.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.