logo

5 macOS Infostealers Making Waves Right Now

ID: 860dde62-d1f7-56e5-9418-7867dc380d16

STIX ID: report--860dde62-d1f7-56e5-9418-7867dc380d16

Feed Name: ReliaQuest Blog

Threat Score
70/100

Date Published: 2023-09-08

Date Updated: 2026-04-29

...
...

ReliaQuest documents a rising trend in macOS-targeting information stealers throughout 2023, profiling five notable MaaS-infostealer families (XLoader, Atomic Stealer, MacStealer, ShadowVault, Realst). The report details infection vectors (DMG/PKG installers, social engineering, malicious links), credential- and crypto-wallet theft techniques (AppleScript/osacscript prompts, Keychain and browser extraction), observed indicators (example IP 94.142.138.177 and POST endpoints such as amos-malware.ru/sendlog and mac.cracked23.site/uploadLog), and recommends mitigations including Gatekeeper restrictions, EDR, web filtering, MFA, patching, and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.