Home News Sophisticated macOS Infostealer Hits Newer Apple Silicon Devices
News

Sophisticated macOS Infostealer Hits Newer Apple Silicon Devices

Researchers have discovered a new, highly-sophisticated macOS malware called DigitStealer that masquerades as a legitimate app called “DynamicLake.” It specifically targets newer Apple Silicon Macs — M2 chips and later — while avoiding older Macs, virtual machines, and Intel-based systems.

DigitStealer’s installation begins with a bash script executed entirely in memory. Before proceeding, it checks the system’s region settings and verifies certain hardware features to ensure it’s running on a non-virtual, M2-or-newer Mac.

If these checks pass, the malware downloads four separate payloads:

  1. A script that asks the user for their macOS password and, if provided, steals credentials, documents, and system files.
  2. Tools that pull data from browser profiles, the macOS keychain, VPN configs, Telegram settings, and crypto wallets (including Ledger, Electrum, Exodus, and others).
  3. A tampered version of the Ledger Live app: the malware replaces its app file so it connects to an attacker-controlled server, giving full access to the user’s crypto wallet.
  4. A persistent backdoor implemented via a “Launch Agent” — this component fetches additional payloads from the attacker’s server on demand. At first, this backdoor is a JavaScript-based automation script, but the attacker can change it dynamically.

To trick users, the malware is packaged as an unsigned disk image named DynamicLake.dmg, served from a fake website mimicking the real DynamicLake app. The installer asks users to drag the file into Terminal, bypassing standard macOS security checks.

The researchers note that the malware’s design shows deep knowledge of macOS internals and a clear intention to evade detection. Because it uses fileless techniques and hardware checks, it leaves minimal traces and can dodge many traditional antivirus tools.

To stay safe, Mac users should:

  • Be very careful where they download apps — especially disk images (.dmg)
  • Avoid dragging unknown or untrusted files into Terminal
  • Use antivirus or security tools that monitor behavior, not just file signatures
  • Always verify the website or GitHub repo before downloading utilities

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles

News

BlackBerry Report: Governments Rely on WhatsApp Despite Widespread Misunderstanding of Messaging Security

A new report from BlackBerry Secure Communications highlights widespread confusion among government...

News

UK Opens Formal Investigation Into Telegram Over CSAM and Child Safety Compliance Concerns

The United Kingdom’s communications regulator, Ofcom, has launched a formal investigation into...

News

Over 1,500 Perforce Servers Still Expose Sensitive Source Code and Critical Data to Attackers

Thousands of internet-facing Perforce P4 servers are still exposing sensitive data due...

News

NGate Malware Hijacks NFC Payments on Android to Steal Card Data

A newly discovered variant of the NGate Android malware is targeting users...