Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Highly Sophisticated macOS DigitStealer Employs Multi-Stage Attacks to Evade detection

A new malware family targeting macOS systems has emerged with advanced detection evasion techniques and multi-stage attack chains.

A new malware family targeting macOS systems has emerged with advanced detection evasion techniques and multi-stage attack chains.

Named DigitStealer, this information stealer uses multiple payloads to steal sensitive data while leaving minimal traces on infected machines.

The malware disguises itself as legitimate software and uses clever methods to bypass Apple’s security protections.

DigitStealer spreads through fake versions of popular macOS applications. The malware was discovered in an unsigned disk image file called DynamicLake.dmg, pretending to be a legitimate utility.

Users are tricked into running a file labeled “Drag Into Terminal.msi” which starts the infection process.

At the time of discovery, no antivirus engines on VirusTotal detected this threat, making it extremely dangerous.

What makes this malware stand out is its use of advanced hardware checks to avoid running on virtual machines or older Mac computers.

Jamf security researchers identified that DigitStealer specifically targets newer Apple Silicon systems, particularly M2 chips and above, while avoiding Intel-based Macs and even M1 devices.

A new malware family targeting macOS systems has emerged with advanced detection evasion techniques and multi-stage attack chains.
Nathan Cole · Thehackingpost

The malware performs extensive system checks before executing its main payload.

The infection starts with a simple bash command that downloads an encoded script from a remote server. Once decoded, this script performs multiple verification steps to ensure it runs only on physical Mac computers with specific hardware features.

Malware workflow (Source -Jamf) The malware checks the system locale and exits if it detects certain countries, potentially to avoid prosecution.

Detection Evasion Through Advanced Hardware Checks

DigitStealer uses sophisticated techniques to detect virtual machines and analysis environments. The malware queries hardware information using system commands and searches for keywords like “Virtual” or “VM” in the output.

If detected, the malware immediately stops execution. The most interesting aspect involves checking for specific Apple Silicon features using the following commands:-

sysctl -n hw.optional.arm.FEAT_BTI sysctl -n hw.optional.arm.FEAT_SSBS sysctl -n hw.optional.arm.FEAT_ECV These commands verify whether advanced ARM processor features exist on the target system. Only M2 or newer chips have these capabilities, effectively limiting infections to the latest Mac computers.

Advertisement

This approach helps the malware avoid detection by security researchers who often use virtual machines or older hardware for analysis.

After passing all verification checks, DigitStealer downloads four separate payloads from remote servers .

Each payload has a specific purpose, from stealing browser credentials and cryptocurrency wallets to modifying legitimate applications like Ledger Live.

The malware uses legitimate Cloudflare services to host payloads, making detection and blocking more difficult.

Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google .

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories