Microsoft Warns macOS Infostealer Campaigns Using ClickFix Lures, Malicious DMGs, and Python Stealers
Microsoft reported that information-stealing malware activity is expanding from Windows to macOS, driven by campaigns observed since late 2025 that rely on social engineering and cross-platform tooling. The activity includes ClickFix-style prompts and malicious DMG installers that deliver macOS-focused infostealer families such as Atomic macOS Stealer (AMOS), MacSync, and DigitStealer, with operators leveraging fileless execution, native macOS utilities, and AppleScript automation to evade defenses and automate collection.
Initial access commonly starts with malicious search ads (e.g., Google Ads) that redirect users to fake sites impersonating legitimate tools and then trick victims into running “fix” steps or installing trojanized software. The malware is assessed to target high-value data including browser credentials and session cookies, iCloud Keychain contents, crypto wallet data, and developer secrets; Microsoft also highlighted growing use of Python-based stealers distributed via phishing for rapid adaptation across heterogeneous environments, citing PXA Stealer (linked to Vietnamese-speaking actors) as an example used in late-2025 campaigns with persistence mechanisms such as registry Run keys or scheduled tasks and Telegram used for command-and-control.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft publicly warns infostealer activity is expanding from Windows to macOS
On 2026-02-04, Microsoft Defender Security Research publicly reported that infostealer operations are increasingly targeting macOS in addition to Windows. The company said cross-platform tooling such as Python and abuse of trusted platforms and native utilities are enabling credential theft, keychain access, and theft of developer secrets that can lead to BEC, supply-chain compromise, and ransomware.
MacOS infostealer campaigns surge using fake ads and ClickFix lures
Since late 2025, Microsoft observed a rise in macOS-focused infostealer campaigns using fake websites promoted through Google Ads, ClickFix-style prompts, malicious DMG installers, and copy-paste Terminal commands. These campaigns delivered families including Atomic macOS Stealer, MacSync, and DigitStealer while relying on fileless execution, native macOS tools, and AppleScript.
WhatsApp hijacking campaign spreads Eternidade Stealer
In November 2025, attackers abused hijacked WhatsApp accounts to propagate Eternidade Stealer through malicious attachments sent to victims' contact lists. The campaign used Python automation and script chains to spread and monitor payment-service-related activity.
Microsoft investigates PXA Stealer phishing tied to Vietnamese-speaking actors
In late 2025, Microsoft investigated Python-based PXA Stealer campaigns delivered through phishing and linked to Vietnamese-speaking threat actors. The activity targeted sectors including government and education and used persistence plus Telegram for command-and-control or exfiltration.
Fake 'Crystal PDF' malvertising campaign targets Windows users
In September 2025, attackers used Google Ads and SEO poisoning to distribute a fake 'Crystal PDF' application for Windows. The malware stole browser cookies, sessions, and credentials, and in some reporting was described as persisting via scheduled tasks and hijacking Chrome and Firefox data.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
5 references tracked. Mallory keeps watching after this page renders.
Macs Under Siege: New Infostealers Spread via WhatsApp & Fake Apps
securityonline.info
Open sourcemacOS Users Hit by Python Infostealers Posing as AI Installers
hackread.com
Open sourceInfostealer threats move beyond Windows to target macOS machines | SC Media
scworld.com
Open sourceMicrosoft: Info-Stealing malware expands from Windows to macOS
securityaffairs.com
Open sourceMicrosoft Warns Python Infostealers Target macOS via Fake Ads and Installers
thehackernews.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


