Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Infostealer Attacks Hit macOS, Abusing Python and Trusted Platforms

Recent campaigns have targeted macOS users, with attackers increasingly utilizing Python-based stealers and exploiting platforms such as WhatsApp and popular PDF utilities. These attacks primarily aim to harvest credentials, browser data, cloud keys, and…

Recent campaigns have targeted macOS users, with attackers increasingly utilizing Python-based stealers and exploiting platforms such as WhatsApp and popular PDF utilities. These attacks primarily aim to harvest credentials, browser data, cloud keys, and cryptocurrency wallets, subsequently transmitting them to attacker-controlled infrastructure.

On macOS, threat actors are employing social engineering and native tools over traditional malware bundles. Users are misled through malicious advertisements and SEO-poisoned search results to download counterfeit applications or follow instructions to input commands in Terminal. This tactic supports campaigns for stealers like DigitStealer, MacSync, and Atomic macOS Stealer (AMOS), which are distributed via trojanized DMG installers, terminal command chains, and fraudulent AI tool installers.

Upon execution, these tools exploit fileless execution, AppleScript (osascript), JXA, and built-in utilities like curl, Base64 decoding, and gunzip to extract browser passwords, keychain entries, crypto wallet files, and developer secrets, while erasing evidence to avoid detection.

The impact of these macOS campaigns is considerable. Compromised browser and keychain credentials facilitate account takeovers across various platforms including email, banking, and enterprise SaaS. Stolen cryptocurrency wallet data can be rapidly drained, and compromised developer keys can lead to source-code theft and cloud infrastructure breaches. These operations often evade traditional signature-based defenses.

Python-based infostealers are gaining popularity due to their adaptability and low entry barrier. Documented phishing-driven campaigns have leveraged Python stealers capable of acquiring credentials, session cookies, authentication tokens, credit card data, and crypto wallet information. Notably, PXA Stealer has been used against government and educational bodies.

Recent campaigns have utilized phishing emails for initial access, registry Run keys and scheduled tasks for persistence, and Telegram channels for command-and-control and data exfiltration. Tactics include obfuscated Python scripts, DLL sideloading, and renamed interpreters masquerading as legitimate processes. Attackers also exploit trusted platforms. A WhatsApp-based campaign, for instance, used a VBScript to deploy a batch file that launches PowerShell for additional payload deployment.

Another campaign impersonated a PDF editor, Crystal PDF, tricking users into downloading a malicious executable. This tool established persistence through scheduled tasks and hijacked browser profiles to extract cookies, session data, and credentials.

Organizations should enhance user awareness and implement robust technical controls. Training should cover malvertising chains, fake installers, and ClickFix-style prompts on macOS, advising against installing unsigned DMGs or unauthorized "terminal fix" tools. Security teams should monitor for unusual Terminal and shell activity, fileless execution patterns, and abnormal access to keychains and browser stores.

On macOS, threat actors are employing social engineering and native tools over traditional malware bundles.
Laura Mitchell · Thehackingpost

On Windows, defenders should be vigilant for obfuscated scripts, renamed interpreters, and DLL sideloading. Microsoft Defender XDR can help detect and block these behaviors across macOS and Windows endpoints, email, and cloud applications.

By enabling cloud-delivered protection and implementing attack surface reduction rules, organizations can enhance their defenses against infostealers.

Indicator Type Description

3e20ddb90291ac17cef9913edd5ba91cd95437da86e396757c9d871a82b1282a SHA-256 DigitStealer payload

42d51feea16eac568989ab73906bbfdd41641ee3752596393a875f85ecf06417 SHA-256 AMOS payload

2c885d1709e2ebfcaa81e998d199b29e982a7559b9d72e5db0e70bf31b183a5f SHA-256 WhatsApp campaign

Advertisement

598da788600747cf3fa1f25cb4fa1e029eca1442316709c137690e645a0872bb SHA-256 Crystal PDF payload

dynamiclake[.]org Domain DigitStealer delivery

barbermoo[.]coupons Domain MacSync C2

alli-ai[.]pro Domain AMOS redirect

bagumedios[.]cloud Domain PXA C2

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories