BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Microsoft Warns of macOS Infostealer Attacks Via Fake Ads

Microsoft warns of rising infostealer malware targeting macOS via fake ads and phishing schemes

  • Microsoft warned in February 2026 that information-stealing malware is aggressively targeting macOS systems through fake ads and installers.
  • Threat actors are using cross-platform languages like Python to deploy stealers such as PXA, Atomic macOS Stealer (AMOS), and Eternidade.
  • The infection chains start with malvertising and social engineering, leading to credential theft from browsers, financial accounts, and cryptocurrency wallets.

In February 2026, Microsoft‘s security team issued a stark warning that infostealer attacks are rapidly expanding to target Apple’s macOS environment. This strategic shift leverages social engineering and trusted platforms to deliver malicious payloads at scale.

- Advertisement -

Since late 2025, attackers have tricked users with “ClickFix” lures distributed via fake sites. Consequently, these sites promote disk image installers for popular tools like DynamicLake and AI applications.

The campaigns deploy malware families including Atomic macOS Stealer (AMOS), MacSync, and DigitStealer. These tools use native macOS utilities and automation to steal web credentials, iCloud Keychain data, and developer secrets.

Microsoft said Python-based stealers allow attackers to rapidly adapt and target diverse systems. These threats typically harvest login credentials, session cookies, and cryptocurrency wallet information.

One example is the PXA Stealer, linked to Vietnamese-speaking actors, which launched phishing campaigns in late 2025. The malware establishes persistence and uses Telegram for command-and-control communications.

- Advertisement -

Meanwhile, other threat groups have weaponized messaging apps like WhatsApp to distribute the Eternidade Stealer. This campaign, documented in November 2025, specifically targets financial and crypto accounts.

Further campaigns involve fake software like Crystal PDF, spread through search engine poisoning. These installers deploy a Windows-based stealer designed to silently collect browser data from Firefox and Chrome.

Organizations are advised to educate users on social engineering and malvertising risks. They must also monitor for suspicious terminal activity and network egress to newly registered domains.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin Dips to $76K As Regulatory, Tech Worries Mount

Bitcoin retreated below $76,000 following declines in the tech-heavy Nasdaq 100 Index.Stalled regulatory progress...

Critical GitHub RCE Flaw Lets Attacker Execute Code via Git Push

A critical vulnerability (CVE-2026-3854) in GitHub allowed remote code execution via a single "git...

Tank OS Secures OpenClaw AI Agents in Containers

Tank OS packages OpenClaw AI agent software into a secure, bootable system image for...

AWS to Offer OpenAI Models, Unveils AI Hiring Agents

Amazon Web Services will begin offering OpenAI's powerful GPT models to its customers, ending...

Illinois Tech Joins Theta EdgeCloud for AI Research

Illinois Institute of Technology joins Theta EdgeCloud's academic network as its 33rd member institution,...

Must Read

How to Choose a Cryptocurrency Exchange: Major Risks and Expert Advice

During the bitcoin frenzy, in late 2017, Coinbase, one of the key players in the global cryptocurrency market, stopped trading operations. At a point...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading