Hackers Use Weaponized DMG Files to Target macOS Users With Infostealer Malware
A new threat targeting macOS users involves weaponized DMG files that deliver an infostealer malware. This malware is designed to steal sensitive information from infected devices, including credit card details and login credentials.
How the Attack Works
- DMG File Distribution: The attackers distribute malicious DMG (disk image) files via cracked forums or unofficial software download sites.
- User Interaction Required: When a user opens the DMG file, it prompts them to drag an app into their Applications folder and approve unknown software in System Settings.
- Malware Installation: If the user complies with these instructions, the malware is installed on the device.
Malware Capabilities
- Data Collection: The infostealer collects various types of sensitive information from the infected macOS devices.
- Persistence Mechanism: It establishes persistence by creating a LaunchAgent to ensure it runs every time the system starts up.
- Command and Control (C2) Communication: The malware communicates with its C2 server to receive further instructions and exfiltrate stolen data.
Detection and Prevention
- Avoid Unofficial Sources: Users should
Read the full article at Cyber Security News
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.





