logo

Hackers Target macOS Users with Malicious Ads Spreading Stealer Malware

ID: b0f96696-ae47-5d13-b40c-ebbf8c9adbf0

STIX ID: report--b0f96696-ae47-5d13-b40c-ebbf8c9adbf0

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-03-30

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Jamf Threat Labs and Moonlock Lab report active malvertising and look-alike websites delivering macOS infostealer malware (Atomic Stealer and a Rust-based Realst-like stealer) through fake DMG installers and sponsored search links; attackers use obfuscated AppleScript/bash payloads and deceptive password prompts to harvest macOS credentials, browser-stored logins, keychain data and cryptocurrency wallet information. The advisory also highlights similar Windows-focused malvertising pushing loaders (FakeBat/EugenLoader) and information stealers like Rhadamanthys, and provides example IOCs (domains such as airci.net and meethub.gg, DMG filenames) and observed TTPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.