{"id":10385,"date":"2026-02-04T10:03:51","date_gmt":"2026-02-04T10:03:51","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/04\/infostealer-campaigns-expand-to-macos-as-attackers-abuse-python-and-trusted-platforms\/"},"modified":"2026-02-04T10:03:51","modified_gmt":"2026-02-04T10:03:51","slug":"infostealer-campaigns-expand-to-macos-as-attackers-abuse-python-and-trusted-platforms","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/04\/infostealer-campaigns-expand-to-macos-as-attackers-abuse-python-and-trusted-platforms\/","title":{"rendered":"Infostealer Campaigns Expand to macOS as Attackers Abuse Python and Trusted Platforms"},"content":{"rendered":"<p>    Infostealer Campaigns Expand to macOS as Attackers Abuse Python and Trusted Platforms<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Infostealer campaigns that once focused mainly on Windows are now expanding aggressively to macOS, using Python and trusted platforms to reach new victims. <\/p>\n<p>Recent attacks show a clear shift: threat actors are abusing online ads, fake apps, and familiar tools to quietly steal credentials, session cookies, and cryptocurrency data from Mac users. <\/p>\n<p>Cross\u2011platform Python stealers and macOS\u2011specific families like DigitStealer, MacSync, and Atomic macOS Stealer (AMOS) are at the center of this surge, turning everyday browsing and software installs into high\u2011risk events for consumers and businesses alike. <\/p>\n<p>These campaigns rely heavily on <a href=\"https:\/\/cybersecuritynews.com\/social-engineering-tactics\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a> to bypass users\u2019 trust. <\/p>\n<p>Malvertising and search\u2011engine\u2011poisoned links lead to fake installers or \u201csystem fix\u201d utilities that appear legitimate, often wrapped in DMG images or seemingly harmless scripts. <\/p>\n<p>Once executed, the payloads quickly move to harvest browser passwords, keychain entries, crypto wallets, and developer secrets. <\/p>\n<p>For organizations, the theft of cloud credentials and source\u2011code access can open the door to deeper compromise, including supply chain attacks and ransomware.<\/p>\n<p>Microsoft researchers <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/02\/02\/infostealers-without-borders-macos-python-stealers-and-platform-abuse\/\" target=\"_blank\" rel=\"noreferrer noopener\">noted<\/a> that recent infostealer waves blend macOS\u2011native techniques with flexible Python tooling to operate across multiple environments. <\/p>\n<p>On macOS, the <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> leans on built\u2011in utilities and AppleScript automation to keep a low profile, while Python stealers are delivered widely through phishing emails and booby\u2011trapped attachments in corporate networks. <\/p>\n<p>At the same time, attackers are weaponizing trusted platforms such as WhatsApp and fake PDF tools to push stealer payloads, making malicious traffic harder to distinguish from normal activity.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism-from-lure-to-silent-data-theft\"><strong>Infection mechanism: from lure to silent data theft<\/strong><\/h2>\n<p>The infection chain typically begins with a lure that looks routine to the victim. <\/p>\n<p>For macOS <a href=\"https:\/\/cybersecuritynews.com\/evolving-phishing-campaigns\/\" target=\"_blank\" rel=\"noreferrer noopener\">campaigns<\/a>, users are steered to spoofed download pages for tools such as DynamicLake or fake AI utilities, or tricked into copy\u2011pasting Terminal commands that supposedly fix browser or system issues. <\/p>\n<p>When the user runs the installer or command, the malware uses native components like curl, base64 decoding, and gunzip to fetch and unpack additional payloads directly into memory, avoiding obvious file drops. <\/p>\n<p>Scripts executed via osascript or <a href=\"https:\/\/cybersecuritynews.com\/zap-memory-leak-issue\/\" target=\"_blank\" rel=\"noreferrer noopener\">JavaScript<\/a> for Automation then enumerate the system, query browsers and keychains, and stage stolen data in temporary archives.<\/p>\n<p>Finally, the infostealer exfiltrates these archives to attacker\u2011controlled domains or command\u2011and\u2011control servers using HTTPS POST requests, often over newly registered or low\u2011reputation infrastructure, completing the compromise with few visible signs to the user.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/infostealer-campaigns-expand\/\">Infostealer Campaigns Expand to macOS as Attackers Abuse Python and Trusted Platforms<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/infostealer-campaigns-expand\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Infostealer Campaigns Expand to macOS as Attackers Abuse Python and Trusted Platforms Infostealer campaigns that once focused mainly on Windows are now expanding aggressively to macOS, using Python and trusted platforms to reach new victims. Recent attacks show a clear shift: threat actors are abusing online ads, fake apps, and familiar tools to quietly steal [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-10385","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10385"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10385"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10385\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10385"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10385"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10385"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}