Weaponized DMG Files Target macOS Users with Infostealer Malware
Article Content
- •Over 65% of new macOS malware in 2025 was infostealers, targeting user credentials.
- •Attackers use weaponized DMG files disguised as legitimate software to deceive users.
- •The infection process often begins with SEO poisoning and compromised torrent links.
Hackers are exploiting macOS users through weaponized DMG files that masquerade as legitimate software installers. This tactic leverages the misconception that Apple devices are immune to malware, allowing attackers to harvest sensitive information quickly. In 2025, over 65% of newly reported macOS malware was classified as infostealers, indicating a significant rise in credential and data theft targeting Apple environments. The attacks primarily initiate via web browsers, utilizing SEO poisoning and compromised links in torrent networks. The infostealers operate rapidly, exfiltrating data before detection, without establishing persistence on the infected systems. This trend highlights a shift in focus from traditional malware tactics to social engineering for initial installation. Current reports indicate that these attacks are ongoing and increasingly sophisticated.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track AMOS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Infostealer Malware Hijacks Claude Sessions, Drains User Accounts Anthropic has alerted users that infostealer malware is compromising Claude accounts by hijacking active login sessions, allowing attackers to deplete usage limits without needing passwords or two-factor authentication. The malware, identified as Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic…
Fake Codex Installer Delivers Suspected AMOS Infostealer via Google Sites A malicious campaign has emerged, using fake Codex installation pages to deliver malware targeting macOS users. The attackers utilize Google Sites to host a fraudulent download portal that appears legitimate, tricking users into executing a command that initiates a multi-stage malware infection. The command, disguised…