Hacking

MacOS Now Prime Target for Expanding Infostealers

Published  ·  3 min read

The Microsoft Defender team has issued an explicit alert that, for many years, malware has been a threat to Windows computer users; however, starting in late 2025, hackers have begun launching extensive attacks against Mac OS users by utilizing cross-platform technologies, such as Python, making their materials both portable and more difficult to eradicate.

The shift isn't subtle. Stealer families such as Atomic macOS Stealer (AMOS), MacSync, and DigitStealer are showing up more frequently, delivered through disk image (.DMG) files that look like legitimate installers. 

Attackers lean heavily on social engineering tricks most notably the "ClickFix" technique, where users are tricked into copying and pasting malicious commands into their Terminal. You might see these scam pop-ups when you visit a hacked website. Often, the scam starts with a malicious ad on Google Ads. An individual search for a specific program (like an AI tool) that he wants to download and clicks on a sponsored ad that appears as though it would take him to the actual program (for example, "Crystal PDF" or "DynamicLake"). 

Instead of arriving at the correct program, the individual instead lands on a fake website trying to get them to install the "ClickFix" program. After pasting the code for the "ClickFix" program, the malware files are installed on the infected machine without detection via native macOS capabilities (like AppleScript or other applications that come with a Mac). The use of these capabilities means that much of the malware is running filelessly and does not leave a lot of obvious evidence of its presence.

Python is proving especially popular with these actors because it's cross-platform, easy to modify, and runs with minimal dependencies. One example is PXA Stealer, tied to Vietnamese-speaking groups. Microsoft spotted notable campaigns in October and December 2025 that arrived via phishing emails, established persistence through registry-like mechanisms (scheduled tasks on macOS), and exfiltrated stolen data over Telegram bots , credentials, cookies, session tokens, credit cards, crypto wallets, and more.

Similar patterns appear elsewhere. Eternidade Stealer has been spread through weaponized WhatsApp messages, leading to takeovers of financial and cryptocurrency accounts (LevelBlue/Trustwave documented this wave in November 2025). On the Windows side, fake PDF tools distributed via SEO-poisoned ads quietly harvest browser data from Chrome and Firefox.

The consequences can snowball quickly: a single infected machine often becomes the entry point for business email compromise, internal network access, supply-chain compromises, or even ransomware deployment. Microsoft stresses that these aren't exotic zero-days, they succeed because people trust search ads, follow urgent-sounding instructions, and run code without second-guessing.

Practical defenses Microsoft recommends include:
1. Train teams (and yourself) to treat any unsolicited "fix this by pasting into Terminal" prompt as highly suspicious—real software rarely asks for that.
2. Be extra wary of sponsored search results for tools or updates; prefer direct downloads from official sites.
3. Watch for unusual Terminal or AppleScript activity, unexpected access to iCloud Keychain, or outbound connections to fresh or odd domains.
4. Use strict browser safeguards, enable phish-resistant MFA, and consider using endpoint monitoring to detect anomalies with file access or network traffic.

In summary, all OS have been equalized via info-stealers. As long as attackers can trick users into the first careless click or paste, the platform matters less than the deception. Staying skeptical of too-good-to-be-true search results and never pasting random commands remains one of the best cheap defenses we have.

Source: The Hacker News

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067