Originally reported by BleepingComputer
TL;DR
Security researchers have identified Infinity Stealer, a new macOS-targeting info-stealing malware that uses ClickFix social engineering lures to trick users into executing Python payloads compiled with Nuitka. The malware harvests system information, browser data, and credentials from infected machines.
New macOS-targeting info stealer using established social engineering techniques. While concerning for Mac users, no evidence yet of widespread deployment or high-value target compromise.
Security researchers have identified a new information-stealing malware campaign targeting macOS users through sophisticated social engineering techniques. The malware, dubbed Infinity Stealer, represents a notable shift in tactics as threat actors increasingly focus on Apple's desktop operating system.
Infinity Stealer employs several technical approaches to evade detection and maintain persistence:
The infection process follows a multi-stage approach designed to bypass macOS security controls:
The use of Nuitka compilation provides several advantages for attackers:
Security teams should implement the following controls to mitigate Infinity Stealer and similar threats:
The emergence of Infinity Stealer reflects broader trends in the macOS threat landscape, including increased targeting of Apple users and evolution of social engineering techniques. Organizations with mixed Windows-macOS environments should ensure security controls provide equivalent protection across both platforms.
Originally reported by BleepingComputer