Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activitysearch-ad-manipulationphishing-campaign-intelligencecommand-and-control-method

Microsoft Warns macOS Infostealer Campaigns Using ClickFix Lures, Malicious DMGs, and Python Stealers

Updated 3mo agoFirst seen Feb 4, 20265 sources

Microsoft reported that information-stealing malware activity is expanding from Windows to macOS, driven by campaigns observed since late 2025 that rely on social engineering and cross-platform tooling. The activity includes ClickFix-style prompts and malicious DMG installers that deliver macOS-focused infostealer families such as Atomic macOS Stealer (AMOS), MacSync, and DigitStealer, with operators leveraging fileless execution, native macOS utilities, and AppleScript automation to evade defenses and automate collection.

Initial access commonly starts with malicious search ads (e.g., Google Ads) that redirect users to fake sites impersonating legitimate tools and then trick victims into running “fix” steps or installing trojanized software. The malware is assessed to target high-value data including browser credentials and session cookies, iCloud Keychain contents, crypto wallet data, and developer secrets; Microsoft also highlighted growing use of Python-based stealers distributed via phishing for rapid adaptation across heterogeneous environments, citing PXA Stealer (linked to Vietnamese-speaking actors) as an example used in late-2025 campaigns with persistence mechanisms such as registry Run keys or scheduled tasks and Telegram used for command-and-control.

Share:
Microsoft Warns macOS Infostealer Campaigns Using ClickFix Lures, Malicious DMGs, and Python Stealers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 4, 20265mo ago

Microsoft publicly warns infostealer activity is expanding from Windows to macOS

On 2026-02-04, Microsoft Defender Security Research publicly reported that infostealer operations are increasingly targeting macOS in addition to Windows. The company said cross-platform tooling such as Python and abuse of trusted platforms and native utilities are enabling credential theft, keychain access, and theft of developer secrets that can lead to BEC, supply-chain compromise, and ransomware.

Nov 1, 20258mo ago

MacOS infostealer campaigns surge using fake ads and ClickFix lures

Since late 2025, Microsoft observed a rise in macOS-focused infostealer campaigns using fake websites promoted through Google Ads, ClickFix-style prompts, malicious DMG installers, and copy-paste Terminal commands. These campaigns delivered families including Atomic macOS Stealer, MacSync, and DigitStealer while relying on fileless execution, native macOS tools, and AppleScript.

WhatsApp hijacking campaign spreads Eternidade Stealer

In November 2025, attackers abused hijacked WhatsApp accounts to propagate Eternidade Stealer through malicious attachments sent to victims' contact lists. The campaign used Python automation and script chains to spread and monitor payment-service-related activity.

Microsoft investigates PXA Stealer phishing tied to Vietnamese-speaking actors

In late 2025, Microsoft investigated Python-based PXA Stealer campaigns delivered through phishing and linked to Vietnamese-speaking threat actors. The activity targeted sectors including government and education and used persistence plus Telegram for command-and-control or exfiltration.

Sep 1, 202510mo ago

Fake 'Crystal PDF' malvertising campaign targets Windows users

In September 2025, attackers used Google Ads and SEO poisoning to distribute a fake 'Crystal PDF' application for Windows. The malware stole browser cookies, sessions, and credentials, and in some reporting was described as persisting via scheduled tasks and hijacking Chrome and Firefox data.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

24 LINKEDOpen in app
Threat actors
1 linked
Affected products
6 linked
MacosWindowsWhatsappFirefoxTelegramPowershell
Organizations
12 linked
Microsoft CorporationKeeper SecurityBlack DuckMeta PlatformsGoogleAmazon Web ServicesBinanceBugcrowdStripeTelegramMercado PagoSecurity Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Microsoft Warns macOS Infostealer Campaigns Using ClickFix Lures, Malicious DMGs, and Python Stealers | Mallory