All Articles

Beyond Windows: How Python Infostealers Are Now Targeting macOS Users and How to Protect Yourself

Michael Jordison Michael Jordison
·

For years, Mac users have operated under a comforting assumption: Apple computers are inherently safer from malware than their Windows counterparts. Unfortunately, that assumption is now being actively exploited.

Microsoft’s Defender Security Research Team identified several Python-based infostealer families targeting macOS since late 2025. These aren’t theoretical risks. They’re active campaigns compromising business users right now.

What are these infostealers and who’s behind them?

Five malware families are actively targeting Mac users:

  • Atomic macOS Stealer (AMOS): the most widespread, sold as malware-as-a-service
  • MacSync: targets browser credentials and keychain data
  • DigitStealer: focuses on cryptocurrency and financial data
  • PXA Stealer: multi-platform stealer with macOS variants
  • Eternidade Stealer: Brazilian-origin stealer expanding globally

These aren’t hobbyist projects. They’re commercial products sold on underground forums, with customer support and regular updates. The barrier to entry for attacking Mac users has dropped dramatically.

How do they get onto your Mac?

Two primary methods dominate:

Fake software downloads

Users searching for legitimate business tools (PDF editors, VPN clients, productivity apps) encounter Google Ads linking to fraudulent websites. The sites look professional. The downloads come as standard DMG installers. Everything feels normal until the malware is running.

ClickFix attacks

Malicious websites display a fake error message and instruct users to open Terminal and paste a command to “fix” the problem. The command downloads and executes the malware. It sounds absurd that anyone would fall for it, but these attacks are surprisingly effective, especially against non-technical users who trust on-screen instructions.

What do they actually steal?

Once installed, these infostealers harvest:

  • Browser passwords and cookies, including saved logins for banking, email, and client portals
  • iCloud Keychain contents, the passwords you thought were safely stored
  • SSH keys and API credentials, access to servers, code repositories, and cloud services
  • Email and messaging app credentials, the keys to business email compromise
  • Cryptocurrency wallet data, direct financial theft

For a professional services firm, a single compromised Mac could expose every client whose credentials are saved in the browser.

What does this mean for your firm?

The consequences go beyond one stolen password:

  • Business Email Compromise (BEC). An attacker in your mailbox can redirect invoices, impersonate partners, and access privileged client communications. The FBI reports BEC scams have cost businesses over $50 billion globally.
  • Supply chain attacks. Compromised developer credentials can be used to attack your clients’ systems.
  • Ransomware deployment. Stolen credentials are frequently sold to ransomware operators.
  • Regulatory exposure. A breach involving client data triggers notification obligations and potential penalties.

How should your firm respond?

Educate your team

  • Train staff to download software only from official sources
  • Warn specifically about Terminal commands. No legitimate website will ever ask you to paste commands into Terminal
  • Run regular phishing simulations that include Mac-specific scenarios

Harden your Macs

  • Keep Gatekeeper enabled. Don’t let staff override it to install unsigned apps
  • Enable FileVault encryption on every device
  • Enforce MFA on all business accounts, not just email
  • Use a password manager instead of relying on browser-saved passwords

Monitor for compromise

  • Deploy endpoint detection on Mac devices, not just Windows
  • Watch for suspicious processes and unusual network connections
  • Have an incident response plan that covers credential rotation

Plan for the worst

  • Maintain a credential rotation procedure for when (not if) a compromise occurs
  • Know which client systems each staff member can access, so you know what to lock down
  • Keep your managed cyber security provider in the loop. Early detection is the difference between an incident and a disaster

The “Macs don’t get malware” era is over. If your firm uses Macs and handles sensitive client data, endpoint protection isn’t optional. It’s table stakes.

Michael Jordison

Want to know where you are actually exposed?

A Cyber Business Review tells you what an attacker would find first and what to fix in what order. Independent, and no switch required.

More on this: Cybersecurity articles · Managed Cybersecurity