Technology

Microsoft warns infostealer malware is 'rapidly expanding beyond traditional Windows-focused campaigns' and targeting Mac devices

2026-02-04 16:05
764 views
Microsoft warns infostealer malware is 'rapidly expanding beyond traditional Windows-focused campaigns' and targeting Mac devices

Hackers are increasingly targeting macOS users with social engineering and infostealers, Microsoft warns.

  1. Pro
  2. Security
Microsoft warns infostealer malware is 'rapidly expanding beyond traditional Windows-focused campaigns' and targeting Mac devices News By Sead Fadilpašić published 4 February 2026

Microsoft shares recommendations and mitigations for macOS users

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

An image of macOS’s app switcher. (Image credit: Image credit: MacFormat)
  • Copy link
  • Facebook
  • X
  • Whatsapp
  • Reddit
  • Pinterest
  • Flipboard
  • Threads
  • Email
Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Tech Radar Get the TechRadar Newsletter

Sign up for breaking news, reviews, opinion, top tech deals, and more.

Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

You are now subscribed

Your newsletter sign-up was successful

An account already exists for this email address, please log in. Subscribe to our newsletter
  • Microsoft warns macOS now faces a rapidly expanding malware and infostealer ecosystem
  • Threat actors use social engineering and malicious ads to deliver DMG installers with variants like DigitStealer, MacSync, and AMOS
  • Attackers target browser sessions, cloud tokens, and developer credentials, while abusing legitimate tools like WhatsApp and Google Ads for propagation

Gone are the days when Windows was always the number one target for cybercriminals - as new research has found macOS is equally as important, with users facing a “rapidly expanding” ecosystem of malware, social engineering tactics, and legitimate but weaponized tools.

A Microsoft report found hackers are using social engineering techniques such as ClickFix (faking a problem and offering a “solution”), and malicious advertising campaigns, to deliver disk image (DMG) installers.

These installers then drop all sorts of nasties, but a few malware variants stand out - DigitStealer, MacSync, and Atomic macOS Stealer (AMOS). Microsoft also said that cross-platform malware, like the ones written in Python, is accelerating infostealer activity since it allows threat actors to quickly adapt across mixed environments.

You may like
  • Side view of data analyst pointing with finger at charts on computer monitor while testing protection of computer systems Dangerous new malware targets macOS devices via OpenVSX extensions - here's how to stay safe
  • Mac New MacOS malware exploits trusted AI and search tools
  • Dark web monitoring New macOS malware chain could cause a major security headache - here's what we know

Long-running aggregation effort

Most of the time, the crooks are interested in stealing sensitive data. However, that no longer means just passwords - it also includes browser sessions, keychains, cloud tokens, and developer credentials, since these secrets enable account takeovers, supply chain compromise, BEC and ransomware attacks and, in some cases, direct cryptocurrency theft.

Microsoft also observed the abuse of legitimate tools and services. For example, it has seen hackers compromising people’s WhatsApp accounts and then using them to propagate infostealers and other malware.

In other cases, they’ve seen malicious ad campaigns running on the Google Ads network, promoting a fake PDF editor that not only deploys an infostealer, but also establishes persistence, too.

The company has also shared a long list of recommendations and mitigations that businesses should follow, including educating employees about phishing, monitoring for suspicious Terminal activity, and inspecting network egress for POST requests to newly registered or suspicious domains.

Are you a pro? Subscribe to our newsletterContact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsorsBy submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

Also, businesses should turn on cloud-delivered protection in Defender, deploy cloud-based machine learning protections, run EDR in block mode, and more.

Best antivirus software headerThe best antivirus for all budgetsOur top picks, based on real-world testing and comparisons

➡️ Read our full guide to the best antivirus1. Best overall:Bitdefender Total Security2. Best for families:Norton 360 with LifeLock3. Best for mobile:McAfee Mobile Security

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

TOPICS Microsoft Sead FadilpašićSocial Links Navigation

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

View More

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Logout Read more Side view of data analyst pointing with finger at charts on computer monitor while testing protection of computer systems Dangerous new malware targets macOS devices via OpenVSX extensions - here's how to stay safe    Mac New MacOS malware exploits trusted AI and search tools    Dark web monitoring New macOS malware chain could cause a major security headache - here's what we know    cyber, attack, hacked word on screen binary code display, hacker Maybe don't trust every Windows Update without checking - hackers hijack images to spread dangerous malware    Representational image of a cybercriminal Glassworm returns once again with a third round of VS code attacks    Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat Watch out, these malicious Android apps have been downloaded 42 million times - and could leave you seriously out of pocket    Latest in Security How to delete your account at Amazon, Facebook, Google or Microsoft Linux users report Microsoft's Visual Studio Code Snap package isn't actually deleting files    Coinbase Visa Coinbase reveals insider breach did take place, customer info compromised    Russia Russian hackers are targeting a new Office 365 zero-day, so patch now or face attack    Side view of data analyst pointing with finger at charts on computer monitor while testing protection of computer systems Dangerous new malware targets macOS devices via OpenVSX extensions - here's how to stay safe    Malwarebytes scam checker is now available directly in ChatGPT. Malwarebytes and ChatGPT team up to check all of those suspicious texts, emails, and URLs with one simple phrase    Representation of AI AI agent social media network Moltbook is a security disaster - millions of credentials and other details left unsecured    Latest in News Person using Steam Machine PC AMD CEO assures us that Steam Machine is on track to ship 'early this year'    Alexa+ on the web Alexa+ is now available for free to everyone in the US – but be cautious    Man holding a mobile phone with warning notification and spam message icon A devious new Apple Pay scam is hitting millions – here’s how to stay safe    A frustrated looking girl playing a video game AMD graphics card makers rumored to be looking at more price hikes    A smartphone showing different family profiles in the Luffu app Fitbit co-founders are launching a new fitness tracking service that caters to the whole family    Samsung Galaxy S21 Ultra review Samsung just quietly ended support for the Galaxy S21 series    LATEST ARTICLES