Python-based infostealers increasingly target macOS

Microsoft reports that Python-based infostealer malware, which has traditionally targeted Windows, is increasingly turning to macOS. The research describes three campaigns. DigitStealer is distributed through fake versions of the DynamicLake software. MacSync relies heavily on social engineering, persuading victims to paste malicious commands straight into Terminal. Atomic Stealer masquerades as an installer for an AI tool. The objective is the same in all three: crypto wallet data, browser passwords and saved credentials, along with developer credentials such as AWS and SSH keys that open the door to corporate systems and data.

What this means for your organisation

Many organisations treat Macs as low-risk equipment and give them weaker monitoring than the Windows estate. Yet Macs are often used by developers and executives, which makes them the machines holding the most keys and the broadest access. These attacks need no vulnerability at all, only a user who installs something or pastes in a command.

Berigo recommends

  • Make sure Macs are covered by the same endpoint monitoring and logging as your Windows machines.
  • Tell staff plainly that commands meant to be pasted into Terminal should never come from a web page.
  • Restrict software installation from sources outside your approved channels.
  • Remove long-lived AWS and SSH keys from Macs used for development and move to short-lived credentials.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch