Microsoft reported that information-stealing malware activity is expanding from Windows to macOS, driven by campaigns observed since late 2025 that rely on social engineering and cross-platform tooling. The activity includes ClickFix-style prompts and malicious DMG installers that deliver macOS-focused infostealer families such as Atomic macOS Stealer (AMOS), MacSync, and DigitStealer, with operators leveraging fileless execution, native macOS utilities, and AppleScript automation to evade defenses and automate collection.
Initial access commonly starts with malicious search ads (e.g., Google Ads) that redirect users to fake sites impersonating legitimate tools and then trick victims into running “fix” steps or installing trojanized software. The malware is assessed to target high-value data including browser credentials and session cookies, iCloud Keychain contents, crypto wallet data, and developer secrets; Microsoft also highlighted growing use of Python-based stealers distributed via phishing for rapid adaptation across heterogeneous environments, citing PXA Stealer (linked to Vietnamese-speaking actors) as an example used in late-2025 campaigns with persistence mechanisms such as registry Run keys or scheduled tasks and Telegram used for command-and-control.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-02-04, Microsoft Defender Security Research publicly reported that infostealer operations are increasingly targeting macOS in addition to Windows. The company said cross-platform tooling such as Python and abuse of trusted platforms and native utilities are enabling credential theft, keychain access, and theft of developer secrets that can lead to BEC, supply-chain compromise, and ransomware.
Since late 2025, Microsoft observed a rise in macOS-focused infostealer campaigns using fake websites promoted through Google Ads, ClickFix-style prompts, malicious DMG installers, and copy-paste Terminal commands. These campaigns delivered families including Atomic macOS Stealer, MacSync, and DigitStealer while relying on fileless execution, native macOS tools, and AppleScript.
In November 2025, attackers abused hijacked WhatsApp accounts to propagate Eternidade Stealer through malicious attachments sent to victims' contact lists. The campaign used Python automation and script chains to spread and monitor payment-service-related activity.
In late 2025, Microsoft investigated Python-based PXA Stealer campaigns delivered through phishing and linked to Vietnamese-speaking threat actors. The activity targeted sectors including government and education and used persistence plus Telegram for command-and-control or exfiltration.
In September 2025, attackers used Google Ads and SEO poisoning to distribute a fake 'Crystal PDF' application for Windows. The malware stole browser cookies, sessions, and credentials, and in some reporting was described as persisting via scheduled tasks and hijacking Chrome and Firefox data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcehackread.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.