Weaponized DMG Files Target macOS Users with Infostealer Malware

Weaponized DMG Files Target macOS Users with Infostealer Malware

First seen 11 Jun 2026, 16:11 UTC HuntressGbhackersCybersecuritynews 80% similarity 64.5

Article Content

Browse articles
ThreatCluster

Hackers are exploiting macOS users through weaponized DMG files that masquerade as legitimate software installers. This tactic leverages the misconception that Apple devices are immune to malware, allowing attackers to harvest sensitive information quickly. In 2025, over 65% of newly reported macOS malware was classified as infostealers, indicating a significant rise in credential and data theft targeting Apple environments. The attacks primarily initiate via web browsers, utilizing SEO poisoning and compromised links in torrent networks. The infostealers operate rapidly, exfiltrating data before detection, without establishing persistence on the infected systems. This trend highlights a shift in focus from traditional malware tactics to social engineering for initial installation. Current reports indicate that these attacks are ongoing and increasingly sophisticated.

Key Points: • Over 65% of new macOS malware in 2025 was infostealers, targeting user credentials. • Attackers use weaponized DMG files disguised as legitimate software to deceive users. • The infection process often begins with SEO poisoning and compromised torrent links.

ThreatCluster AI

Timeline

2025-01-01
Rise in macOS infostealer malware reported
Reports indicated that over 65% of newly identified macOS malware was classified as infostealers, marking a significant trend in cyber threats against Apple devices.
Huntress
2026-06-10
Huntress article published
Huntress detailed the use of deceptive installers and weaponized DMG files targeting macOS users, emphasizing the shift in attack strategies.
Huntress
2026-06-11
Cybersecuritynews article published
Cybersecuritynews reported on the ongoing use of weaponized DMG files to exploit macOS users, reinforcing the urgency of the threat.
Cybersecuritynews

Community

Browse all →