{"id":5303,"date":"2025-07-12T10:01:37","date_gmt":"2025-07-12T10:01:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/12\/infostealers-actively-attacking-macos-users-in-the-wild-to-steal-sensitive-data\/"},"modified":"2025-07-12T10:01:37","modified_gmt":"2025-07-12T10:01:37","slug":"infostealers-actively-attacking-macos-users-in-the-wild-to-steal-sensitive-data","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/12\/infostealers-actively-attacking-macos-users-in-the-wild-to-steal-sensitive-data\/","title":{"rendered":"Infostealers Actively Attacking macOS Users in The Wild to Steal Sensitive Data"},"content":{"rendered":"<p>    Infostealers Actively Attacking macOS Users in The Wild to Steal Sensitive Data<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The cybersecurity landscape is witnessing an alarming surge in macOS-targeted information-stealing malware, marking a significant shift from the traditional Windows-centric threat model.<\/p>\n<p>These sophisticated infostealers are rapidly evolving to exploit macOS environments with unprecedented precision, targeting valuable data including browser credentials, cookies, and autofill information that serve as gateways for <a href=\"https:\/\/cybersecuritynews.com\/ransomware-groups-attacking-satellite\/\" target=\"_blank\" rel=\"noreferrer noopener\">ransomware groups<\/a> and initial access brokers.<\/p>\n<p>The emergence of these macOS infostealers represents a calculated response to the growing enterprise adoption of Apple systems. Unlike their Windows counterparts, these threats leverage platform-specific attack vectors to bypass traditional security measures.<\/p>\n<p>The malware\u2019s primary objective centers on harvesting browser-stored data, host information, and installed application details, creating comprehensive digital fingerprints of infected systems.<\/p>\n<p>Flashpoint Intel Team analysts <a href=\"https:\/\/flashpoint.io\/blog\/the-rising-threat-of-macos-infostealers-what-you-need-to-know-to-defend-against-them\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> four prominent strains dominating the current threat landscape: Atomic Stealer, recognized as the most prevalent Malware-as-a-Service offering; Poseidon Stealer, a sophisticated variant with connections to Atomic\u2019s development team; Cthulu, another significant MaaS platform; and Banshee, contributing to the expanding ecosystem.<\/p>\n<p>These families collectively process over 300 million credential sets monthly, with approximately 50 million unique credentials and 6 million never-before-seen entries captured across 1.5 million infected hosts.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Technical Infection Mechanisms and System Exploitation<\/strong><\/h2>\n<p>The infection methodology employed by these infostealers demonstrates sophisticated understanding of macOS architecture.<\/p>\n<p>The malware primarily utilizes AppleScript for generating deceptive authentication prompts, exploiting user trust in legitimate system dialogs.<\/p>\n<p>A typical infection sequence involves:-<\/p>\n<pre class=\"wp-block-code\"><code>display dialog \"System Update Required\" with title \"macOS Security Update\" buttons {\"Cancel\", \"Install\"} default button \"Install\"<\/code><\/pre>\n<p>Following successful social engineering, the malware executes system profiler commands to enumerate hardware and software configurations.<\/p>\n<p>The <code>system_profiler SPHardwareDataType<\/code> command reveals system specifications, while <code>system_profiler SPApplicationsDataType<\/code> catalogs installed applications, providing attackers with detailed <a href=\"https:\/\/cybersecuritynews.com\/morphing-meerkat-phaas-using-dns-reconnaissance\/\" target=\"_blank\" rel=\"noreferrer noopener\">reconnaissance<\/a> data.<\/p>\n<p>Data exfiltration occurs through HTTP POST requests to command-and-control servers, with collected information compressed using standard archiving utilities.<\/p>\n<p>The malware typically targets Safari\u2019s keychain entries, Chrome\u2019s Local State files, and Firefox\u2019s logins.json databases, systematically harvesting stored credentials before transmission to remote infrastructure.<\/p>\n<p>This technical sophistication, combined with the rapid evolution of detection evasion techniques, positions macOS infostealers as a formidable threat requiring immediate organizational attention and enhanced <a href=\"https:\/\/cybersecuritynews.com\/strengthening-security-measures-in-digital-advertising-platforms\/\" target=\"_blank\" rel=\"noreferrer noopener\">security measures<\/a>.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\">Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -&gt;\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=braodo_stealer&amp;utm_content=demo_1&amp;utm_term=250625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Try ANY.RUN now<\/strong><\/a><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/infostealers-actively-attacking-macos-users\/\">Infostealers Actively Attacking macOS Users in The Wild to Steal Sensitive Data<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/infostealers-actively-attacking-macos-users\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Infostealers Actively Attacking macOS Users in The Wild to Steal Sensitive Data The cybersecurity landscape is witnessing an alarming surge in macOS-targeted information-stealing malware, marking a significant shift from the traditional Windows-centric threat model. These sophisticated infostealers are rapidly evolving to exploit macOS environments with unprecedented precision, targeting valuable data including browser credentials, cookies, and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-5303","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5303"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5303"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5303\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5303"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5303"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5303"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}