DigitStealer Infostealer Targets macOS, Revealing Critical Infrastructure Vulnerabilities
DigitStealer is a macOS-targeting infostealer that has been identified as increasingly active. It exhibits a predictable command-and-control (C2) setup, leading to structural weaknesses in the operators' infrastructure. While the malware demonstrates…
DigitStealer is a macOS-targeting infostealer that has been identified as increasingly active. It exhibits a predictable command-and-control (C2) setup, leading to structural weaknesses in the operators' infrastructure. While the malware demonstrates technical sophistication on endpoints, its backend has been relatively easy to fingerprint and track due to the reuse of certain providers, protocols, and registration patterns.
The malware is delivered through spoofed disk images that impersonate legitimate applications, such as the DynamicLake productivity app. It is also distributed via fake websites and installer flows to deceive users into executing the malware. DigitStealer heavily utilizes macOS automation and native tools, executing most logic in memory and using staged payloads.
DigitStealer was first detailed by Jamf Threat Labs in November 2025. It is a multi-stage macOS infostealer that targets browser data, keychain contents, files, and at least 18 different cryptocurrency wallets. The malware performs environment checks to avoid sandboxes and prefers Apple Silicon M2 and newer systems. Once installed, it executes several payload stages, including deceptive password prompts and data collection. A Launch Agent establishes persistence, turning the stealer into a backdoor for operators.
C2 Protocol and Cryptographic Challenge
The C2 communication involves a set of fixed API paths, such as /api/credentials and /api/grabber, used for various operations like sending stolen credentials and uploading files. Infected hosts send the hardware UUID, hashed with MD5, to the C2 every 10 seconds. The C2 presents a cryptographic challenge, requiring the client to produce a value that matches a required pattern before issuing a session token.
Researchers can detect this behavior by scanning for JSON structures exposing challenge and complexity fields. The consistent API structure and polling interval create a behavioral fingerprint for security teams.
DigitStealer's infrastructure reveals patterns, such as a preference for .com domains and a single hosting network. Community findings have highlighted C2 domains with similar registration and hosting traits. Platforms like Hunt.io and WHOIS services indicate many domains resolve to IP addresses on a Swedish hosting provider and ASN, fronted by nginx, and using a narrow set of OpenSSH versions.
The use of Let's Encrypt for TLS certificates and privacy-friendly providers for nameservers is common. All IPs are hosted on the ab stract ltd network in Sweden, providing a pattern for clustering servers.
DigitStealer is a macOS-targeting infostealer that has been identified as increasingly active.
Analysis suggests DigitStealer is controlled by a single operator or a closely knit group, given the centralized ASN, recurring domain patterns, and constrained registrar choices. The uniformity of its infrastructure suggests it's not a broadly rented service. Security teams can follow the trail left by this uniformity to track the malware's operations.
IP Address Domain(s) ASN / Owner
80.78.30.90 beetongame[.]com, binance.comtr-katilim[.]com, yourwrongwayz[.]com, chiebi[.]com ab stract ltd
80.78.30.191 tribusadao[.]com, theinvestcofund[.]com, cekrovnyshim[.]com ab stract ltd
80.78.30.146 ebemvsextiho[.]com, th6969[.]top ab stract ltd
80.78.22.140 flowerskitty[.]com ab stract ltd
80.78.22.131 ironswordzombiekiller[.]com, siriustimes[.]info, siriustimes[.]rocks, bchat[.]cc, red-letter[.]org ab stract ltd / bchat[.]cc – Immaterialism
80.78.31.72 rompompomsigma[.]com ab stract ltd
80.78.27.104 diamondpickaxeforge[.]com ab stract ltd
Based on reporting by GBHackers.
