Threat actors are increasingly abusing trusted platforms and familiar workflows to steal credentials and session data, with infostealer operations expanding beyond Windows into macOS. Reported campaigns use malvertising, search-engine poisoning, fake apps, and DMG-packaged installers to deliver cross-platform Python-based stealers and macOS-focused families (including AMOS, DigitStealer, and MacSync) that target browser passwords, Keychain data, crypto wallets, and developer/cloud secrets; this credential theft can enable follow-on compromise such as source-code access abuse, supply-chain intrusion, and ransomware.
Separately reported phishing activity shows similar “trust abuse” patterns: a fake Dropbox credential-harvesting chain uses benign-looking PDFs and legitimate cloud hosting (e.g., Vercel Blob storage) to evade scanners and email controls, then exfiltrates captured credentials via Telegram. Another technique, ConsentFix/AuthCodeFix, abuses the OAuth 2.0 authorization-code flow by coercing victims into copying a localhost redirect URL containing an authorization code (often for implicitly trusted first-party apps like Azure CLI), allowing attackers to exchange it for tokens and effectively bypass MFA and Conditional Access protections.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft researchers observed infostealer operations increasingly targeting macOS with cross-platform Python tooling and macOS-native techniques delivered through malvertising, fake apps, phishing, and abuse of trusted platforms. The malware uses built-in macOS automation and utilities to steal credentials, cookies, keychain data, and crypto-related information for exfiltration to attacker-controlled infrastructure.
A phishing campaign impersonating Dropbox was reported using procurement-themed emails with a PDF attachment that links to a second PDF hosted on Vercel Blob storage, which then redirects victims to a fake Dropbox login page. The page captures credentials, collects victim IP and geolocation data, and exfiltrates the stolen information through a Telegram bot.
Researchers described ConsentFix, also called AuthCodeFix, a phishing method that tricks victims into pasting a localhost redirect URL containing a Microsoft OAuth authorization code for a trusted first-party app such as Azure CLI. Attackers can exchange the stolen code for tokens without triggering a new Conditional Access evaluation, enabling MFA and policy bypass.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.