On this page

macOS Infostealers: How Apple Devices Became a Target for Credential Theft
19 min

macOS Infostealers: How Apple Devices Became a Target for Credential Theft

For many years, infostealer activity was associated mainly with Windows. That has changed. macOS is now a serious target for credential theft, session theft, crypto-wallet compromise, developer-secret exposure, and enterprise account takeover. The reason is simple: Macs are widely used by executives, developers, designers, contractors, startup teams, and employees with access to high-value SaaS, cloud, source-code, finance, and communication systems.

Modern macOS stealers are built around the same criminal goal as Windows stealers: collect valuable identity data from a device and turn it into a sellable log. The difference is the operating environment. macOS stealers need to work around Apple security controls, user permission prompts, Keychain behavior, browser storage, app bundle formats, disk image installers, Terminal workflows, and user trust in Apple’s platform. As attackers adapt, macOS has become a growing part of the credential theft economy.

Microsoft reported in February 2026 that infostealer threats are expanding beyond Windows-focused campaigns into macOS environments, cross-platform Python malware, and abuse of trusted platforms and utilities. The same report highlights macOS-targeted families such as DigitStealer, MacSync, and Atomic macOS Stealer, as well as campaigns that steal browser data, session data, cryptocurrency wallets, developer secrets, SSH keys, Kubernetes configurations, and AWS credentials.

This shift matters for security teams because macOS endpoints often sit close to sensitive business workflows. A Mac used by a developer may contain cloud credentials, GitHub tokens, SSH keys, package registry secrets, Docker configurations, and Kubernetes files. A Mac used by an executive may contain authenticated browser sessions to email, finance tools, CRM systems, password managers, and internal SaaS applications. A Mac used by a contractor may bridge personal browsing and corporate access. A single stealer infection can become a business incident, even when the malware runs for only a few minutes.

What makes macOS stealers different

macOS stealers use a different playbook from traditional Windows commodity stealers. Windows stealers often rely on executable files, loaders, cracked software, malicious ads, and broad malware-as-a-service distribution. macOS stealers also use fake installers and malvertising, but they place heavier emphasis on social engineering, fake applications, disk image files, AppleScript, Terminal commands, password prompts, and user-approved execution.

The most effective macOS stealers exploit user trust. A victim may believe they are installing a productivity tool, a crypto app, a VPN, a browser update, a PDF utility, a video tool, a disk cleanup app, or a development utility. Some campaigns use fake troubleshooting content that tells the victim to paste a command into Terminal. Microsoft reported in May 2026 that ClickFix-style campaigns are targeting macOS users with fake utility fixes and malicious Terminal commands. The campaign moved from disk image installation toward instructions that use native macOS utilities to retrieve remotely hosted content and execute script-based loaders.

This style of attack is effective because it turns the victim into part of the execution chain. The malware does less technical exploitation and more persuasion. It asks the user to install, approve, paste, enter a password, grant access, or bypass a warning. For defenders, this means endpoint detection has to cover both malware behavior and suspicious user-driven workflows, especially Terminal activity, AppleScript execution, curl-based downloads, encoded scripts, and unexpected app launches from user directories.

The main macOS infostealer families

The macOS stealer landscape is smaller than the Windows landscape, but it is evolving quickly. The most important families today include Atomic macOS Stealer, also known as AMOS, Banshee Stealer, Cthulhu Stealer, Poseidon Stealer, MetaStealer, RealStealer, KeySteal, CherryPie, MacStealer, Shamos, DigitStealer, MacSync, and several Python-based or cross-platform stealers that can target macOS alongside Windows.

SentinelOne reported continued prevalence and adaptation among macOS infostealers such as KeySteal, Atomic InfoStealer, and CherryPie, and described the challenge they create for macOS enterprise users. Unit 42 reported that its Cortex XDR telemetry identified Atomic Stealer, Poseidon Stealer, and Cthulhu Stealer as three particularly prevalent macOS stealers, and focused its research on how those families interact with macOS operating system behaviors.

Atomic macOS Stealer, or AMOS, is the best-known modern macOS stealer. It has been sold as malware-as-a-service and has been distributed through fake apps, malicious websites, fake installers, malvertising, and social engineering campaigns. AMOS targets browser data, passwords, cookies, crypto wallets, files, system information, and other sensitive data. In recent campaigns, attackers have used fake software pages, fake GitHub repositories, search ads, AI-themed lures, and terminal-command instructions to deliver it. BleepingComputer reported in 2026 that AMOS was being distributed through a fake AI app campaign and described infostealers like AMOS as part of a mature cybercrime economy built around harvesting, trading, and operationalizing stolen digital identities.

Banshee Stealer is another important macOS family. Elastic reported that Banshee targets system information, browser data, and cryptocurrency wallets, and that it was designed to function across both macOS x86_64 and ARM64 architectures. Elastic also reported that Banshee was offered at a subscription price of $3,000 per month, which shows how macOS stealers are being packaged as premium criminal tools. Check Point later reported that Banshee was first made public in July 2024 and targets browser and login credentials, cryptocurrency wallets, and sensitive file data.

Cthulhu Stealer is a macOS stealer that gained attention in 2024 and 2025. It has been distributed through fake applications and social engineering, and it targets user data, credentials, and crypto-related assets. Unit 42 included Cthulhu among the prevalent macOS stealers it observed alongside Atomic and Poseidon.

Poseidon Stealer is another family commonly discussed with AMOS and Cthulhu. It focuses on browser data, credentials, and other local secrets, and it appears in the same broader trend of macOS malware built for theft from consumer and enterprise users. Its importance comes from its presence in telemetry and its fit with the growing market for macOS-focused stealer logs.

KeySteal, CherryPie, and RealStealer represent the broader set of macOS malware families adapting to Apple environments. SentinelOne’s research on these families highlights the continued evolution of macOS infostealers and the challenge of detecting rapidly changing strains even as Apple updates its XProtect signatures.

DigitStealer and MacSync are especially relevant because Microsoft highlighted them in its 2026 reporting on macOS and Python-based infostealer campaigns. These families show that attackers are building macOS-specific stealers while also using cross-platform languages and trusted-platform abuse to reach mixed environments.

Comparison table: major macOS stealers

Infostealer family Status Main targets Common delivery Business model Current risk
Atomic macOS Stealer / AMOS Active and highly prominent Browser data, cookies, passwords, crypto wallets, files, system data Fake apps, fake websites, malvertising, fake GitHub repositories, Terminal lures Malware-as-a-service Critical
Banshee Stealer Active and premium-positioned Browser data, login credentials, crypto wallets, sensitive files Fake apps, phishing pages, trojanized installers Malware-as-a-service High
Cthulhu Stealer Active/recent Credentials, browser data, crypto wallets, user files Fake applications and social engineering Commodity macOS stealer High
Poseidon Stealer Active/recent Browser credentials, cookies, wallets, local data Fake installers and macOS social engineering Commodity macOS stealer High
MetaStealer macOS Active/recent Credentials, browser data, files Fake business or productivity files Commodity macOS stealer Medium to high
KeySteal Active/recent Keychain-related data, credentials, local secrets macOS malware campaigns and trojanized apps Private or commodity tooling Medium to high
CherryPie Active/recent Credentials, browser data, local secrets Trojanized apps and social engineering Private or commodity tooling Medium
RealStealer Active/recent Browser data, credentials, files Fake apps and social engineering Commodity stealer Medium
MacStealer Historical/recent relevance Browser data, Keychain data, wallets, files Fake apps, underground sales Commodity stealer Medium
Shamos AMOS-related variant activity Browser data, credentials, wallets, files AMOS-style social engineering and fake software Variant or related stealer activity High
DigitStealer Active/recent in Microsoft reporting Credentials, browser data, wallets, developer secrets Fake DMGs, fake apps, platform abuse macOS stealer Medium to high
MacSync Active/recent in Microsoft reporting Credentials, browser data, wallets, developer secrets Fake DMGs, fake apps, platform abuse macOS stealer Medium to high

This table should be read as a practical risk comparison rather than a strict code-family map. macOS stealer naming is fluid, and some names refer to malware families, some to variants, some to campaigns, and some to underground product brands. The useful question for defenders is what the malware steals, how it reaches users, and how the stolen data can be used.

The data macOS stealers want most

macOS stealers focus on identity data, browser data, crypto assets, application secrets, and developer credentials. Browser data remains the central target. Chrome, Firefox, Brave, Edge, Opera, and Safari can all contain saved credentials, cookies, autofill data, browsing history, and active sessions. These artifacts can expose personal accounts, enterprise SaaS tools, cloud consoles, email, collaboration platforms, social media accounts, and financial services.

Cookies and session data are especially valuable. A stolen password may trigger additional authentication controls. A stolen session can sometimes allow direct account access while the session remains valid. This turns a local endpoint infection into a cloud identity problem. For organizations that rely on SSO, SaaS tools, browser-based admin portals, and long-lived sessions, browser theft from a Mac can have the same business impact as a direct compromise of corporate credentials.

Keychain access is another major area of interest. macOS Keychain stores passwords, certificates, keys, secure notes, Wi-Fi secrets, app credentials, and other sensitive material. Some stealers attempt to access Keychain data directly. Others use fake prompts to trick users into entering their macOS password. This is one of the clearest examples of how macOS stealers combine technical collection with social engineering.

Crypto wallets are a major target because they provide immediate financial value. Stealers look for wallet browser extensions, wallet desktop applications, recovery phrases, wallet files, and clipboard data. AMOS, Banshee, Cthulhu, and similar families are often promoted or reported around their ability to collect cryptocurrency-related data. Elastic’s Banshee analysis states that the malware targets browser data and cryptocurrency wallets, while Check Point’s reporting describes Banshee’s ability to steal browser and login credentials, cryptocurrency wallets, and sensitive files.

Developer secrets make macOS stealers especially important for companies. Many developers use Macs as primary workstations. Those machines may contain SSH keys, Git credentials, GitHub tokens, cloud access keys, npm tokens, Docker credentials, Kubernetes configurations, API keys, Terraform variables, and local environment files. Microsoft’s 2026 research specifically highlights attacker interest in developer secrets, SSH keys, Kubernetes configurations, and AWS credentials. This means a macOS stealer infection can create supply-chain risk, cloud-account risk, and source-code exposure risk.

Common delivery methods

The most common macOS stealer delivery method is fake software. Attackers create pages that look like legitimate apps, utilities, AI tools, browser extensions, productivity software, VPN clients, password tools, crypto apps, video tools, or developer utilities. The victim downloads a DMG or ZIP file, opens an app bundle, and follows the instructions. The malware may use a convincing interface, a fake error message, or a password prompt to complete the theft.

Malvertising and SEO poisoning increase the effectiveness of these fake software campaigns. Attackers buy search ads or manipulate search results so that malicious pages appear when users search for software downloads or technical help. Huntress reported a campaign involving AMOS in which attackers used search and AI-trust abuse to push victims toward malicious instructions, describing the evolution from fake installers to poisoned help content that appears where users look for answers.

ClickFix-style attacks are now a major macOS concern. In these campaigns, victims are told to copy and paste a command into Terminal to fix a problem, verify access, update software, optimize disk space, or complete a setup step. Microsoft’s May 2026 reporting describes fake macOS utility lures that instruct users to run Terminal commands which use native utilities to retrieve remote content and execute script-based loaders.

Fake GitHub repositories have also become useful to attackers. A fake repository can impersonate a popular tool or project, include professional-looking documentation, and direct users to a malicious download or Terminal command. This delivery method is especially relevant for developers because GitHub carries trust in technical communities.

Phishing remains relevant, especially for business users. A phishing email can deliver an archive, fake document, DMG, or link to a malicious page. Some campaigns use invoices, HR documents, collaboration requests, job offers, design files, PDF utilities, or business software themes. Microsoft’s broader reporting also describes platform abuse, including trusted services and utilities used to distribute credential-stealing payloads.

Technical behavior

A macOS stealer typically starts with execution through a user-approved app, script, or command. Once launched, it collects system information such as username, hostname, operating system version, hardware architecture, IP details, running processes, installed browsers, and security tooling. This metadata helps attackers identify valuable machines and filter logs by geography, role, device type, or organization.

The stealer then moves into collection. It may search browser profile folders, cookie databases, login data files, extension folders, wallet directories, desktop files, document folders, screenshots, notes, messaging app data, and developer configuration files. Some stealers call native tools or scripts. Others use embedded binaries, AppleScript, shell commands, Python, Swift, Go, or Objective-C components.

Credential access often involves user deception. A fake macOS password prompt can ask the victim to enter their system password for installation, update, verification, or repair. Once entered, the password may allow the malware to access protected data or escalate collection. This pattern makes user interface deception a core technical feature of macOS stealers.

Persistence varies by family. Many stealers focus on quick theft and exit. Some families and variants add persistence through LaunchAgents, login items, scheduled jobs, or background components. Reports around AMOS have described capability expansion into more persistent access in some versions, which raises the risk from quick data theft to longer-term compromise.

Exfiltration typically sends collected data to attacker-controlled infrastructure. Some campaigns use HTTP requests to command-and-control servers. Others use Telegram, Discord, cloud services, or other trusted platforms as part of the delivery or exfiltration chain. The result is a packaged log that can be used directly or sold to another actor.

Why macOS stealer logs are valuable

A macOS stealer log can contain enough data to impersonate the victim across personal and business systems. Browser cookies can open SaaS sessions. Saved passwords can expose personal and corporate accounts. Crypto wallet files can lead to immediate theft. Keychain material can expose app secrets. Developer files can expose cloud environments and source-code systems.

For a company, the most important risk is identity takeover. A compromised Mac used by an employee can expose access to Google Workspace, Microsoft 365, Slack, GitHub, Salesforce, HubSpot, cloud dashboards, finance tools, HR platforms, customer support systems, and internal admin portals. The attacker may use stolen sessions to enter these systems from a different device, making the original infection only the starting point.

Developer compromise creates an even broader risk. Stolen SSH keys, GitHub tokens, cloud keys, Kubernetes configurations, package registry tokens, and local environment files can lead to code theft, secret exposure, cloud abuse, supply-chain compromise, and production environment access. This is one of the reasons macOS infostealers deserve attention from engineering leadership, cloud security teams, and product security teams.

Crypto theft remains a major driver in the macOS stealer market. Many Mac users in technology, startup, Web3, and investment communities hold wallet applications or browser wallet extensions. Attackers understand this audience and tailor lures around AI tools, developer utilities, crypto software, productivity apps, and business tools.

Business impact

The impact of a macOS stealer infection extends beyond malware removal. Once data leaves the device, the attacker can use it even after the malicious file is deleted. The response must cover the endpoint, the user identity, active sessions, tokens, cloud keys, developer secrets, wallets, and any accounts accessed from the device.

For a corporate user, password resets alone provide partial coverage. Security teams also need to revoke browser sessions, invalidate OAuth tokens, review SSO activity, rotate API keys, inspect GitHub and cloud access, review mailbox rules, check for suspicious SaaS logins, and examine the endpoint for persistence. For developers, teams should rotate SSH keys, Git credentials, cloud CLI credentials, Kubernetes files, npm or package tokens, Docker credentials, and environment secrets.

The business impact also depends on the victim’s role. An executive infection may expose email, finance, board materials, identity documents, and SaaS sessions. A developer infection may expose source code, deployment systems, and cloud credentials. A marketing user infection may expose ad accounts and social media platforms. A finance user infection may enable invoice fraud and business email compromise.

Detection opportunities

macOS stealer detection should focus on suspicious behavior around Terminal, AppleScript, browser data access, credential prompts, file collection, and outbound communication. Security teams should pay close attention to commands that download and execute remote scripts, such as curl or similar utilities combined with shell execution. Encoded scripts, temporary files, unusual LaunchAgents, suspicious login items, and unexpected access to browser profile directories can also be useful signals.

Monitoring should include access to browser credential databases, cookie stores, wallet folders, Keychain-related commands, screenshots, archive creation, and unusual file reads from Desktop, Documents, Downloads, and developer directories. Endpoint tools should also watch for fake app bundles launched from Downloads, mounted DMGs with suspicious names, unsigned or newly signed applications, and scripts executed immediately after a user visits a software download or troubleshooting page.

Network detection can help identify communication with known command-and-control infrastructure, Telegram APIs, Discord webhooks, newly registered domains, and suspicious cloud-hosted payloads. This layer has limits because attackers rotate infrastructure and use trusted platforms. Behavioral detection on the endpoint and identity-layer monitoring remain essential.

Identity monitoring should look for new device fingerprints, unusual geographies, session reuse, impossible travel, suspicious OAuth grants, new mailbox rules, unexpected MFA changes, and logins from residential proxies or automation frameworks. Since the stolen material often leaves the machine quickly, identity-layer alerts may be the first visible sign of compromise.

Prevention priorities

The most effective prevention starts with software-source control. Users should download applications from official vendor sites, managed app catalogs, trusted MDM systems, or the Mac App Store where appropriate. Companies should reduce the use of unmanaged downloads, cracked software, unsigned utilities, and random GitHub “download” links.

Application control and device management matter. MDM policies can restrict execution from risky locations, manage Gatekeeper settings, enforce FileVault, control browser extensions, require EDR coverage, and standardize approved software installation paths. Developer workstations need additional controls because they hold higher-value secrets.

Security training should use examples that match current macOS attacks. Users should recognize fake Terminal fix instructions, fake CAPTCHA commands, fake disk cleanup utilities, fake AI tools, fake crypto apps, fake PDF converters, and suspicious DMG installers. Training should emphasize that attackers now use professional-looking pages, search ads, AI-style answers, GitHub repositories, and trusted collaboration platforms.

For developers, prevention should include secret hygiene. API keys, SSH keys, cloud credentials, package tokens, and production secrets should be stored, scoped, rotated, and monitored carefully. Short-lived credentials, hardware-backed authentication, least privilege, and secret scanning can reduce the blast radius of a stolen workstation.

Comparison framework for macOS stealers

The best way to compare macOS stealer families is to evaluate them across platform fit, delivery sophistication, collection scope, credential access method, enterprise impact, evasion, and remediation complexity.

Dimension Low Medium High
Delivery sophistication Simple fake app Fake app plus phishing or malvertising Search poisoning, ClickFix, fake GitHub, AI-trust abuse, multi-stage scripts
Collection scope Browser passwords only Browsers, cookies, wallets, files Browser sessions, Keychain data, wallets, developer secrets, cloud credentials
Enterprise impact Mostly consumer theft Some SaaS and email exposure Developer secrets, cloud access, SSO sessions, source-code systems
Credential access method Basic file theft Browser and app data extraction Password prompts, Keychain access, session theft, token theft
Persistence One-time execution Basic LaunchAgent or login item Backdoor behavior, repeat collection, command execution
Evasion Basic packaging Obfuscation and signed components Rapid updates, sandbox checks, trusted-platform abuse
Remediation complexity Password reset Password reset and session revocation Full identity, token, cloud, developer-secret, and endpoint response

This framework helps teams separate a basic grabber from a high-risk macOS stealer that can expose corporate systems. It also helps executives understand why a Mac infection can become an identity, cloud, and supply-chain issue.

How macOS stealers fit into the broader infostealer economy

macOS stealers are becoming more professional because the market rewards them. Attackers follow valuable users, and valuable users increasingly rely on Macs. The rise of macOS in engineering, executive, startup, design, and security teams makes the platform attractive. The growth of malware-as-a-service makes it easier for criminals to buy access to macOS-specific tools without building them from scratch.

The ecosystem also benefits from cross-platform development. Python, Go, Rust, and other languages allow attackers to build tooling that works across different operating systems or can be adapted quickly. Microsoft’s reporting highlights the role of Python-based stealers and cross-platform campaigns in expanding infostealer activity beyond traditional Windows environments.

The result is a market where Windows remains the largest stealer environment, while macOS becomes a high-value growth area. The volume may be lower, but the value per victim can be high. A single compromised developer Mac can be worth more than many consumer infections.

Conclusion

macOS infostealers are now a meaningful part of the credential theft economy. They combine social engineering, fake software, Terminal-based lures, browser data theft, Keychain targeting, crypto-wallet theft, and developer-secret collection. Families such as AMOS, Banshee, Cthulhu, Poseidon, KeySteal, CherryPie, DigitStealer, and MacSync show that attackers are investing in macOS-specific tooling and distribution.

For security teams, the main lesson is clear: a macOS stealer infection is an identity incident, a potential cloud incident, and in developer environments, a potential supply-chain incident. Endpoint cleanup is only one part of the response. The stolen data may include sessions, tokens, credentials, wallet material, SSH keys, cloud secrets, and application access that remain useful after the malware disappears from the machine.

The practical response is to treat Macs as first-class security assets. They need endpoint detection, managed software installation, browser and identity controls, developer-secret protection, session revocation workflows, cloud-key rotation procedures, and user training based on current macOS lures. As attackers continue to professionalize macOS stealers, organizations that combine endpoint, identity, cloud, and user-behavior defenses will be in the strongest position to reduce damage.

Ran Geva
Ran Geva
linkedin
Spread the news

Check your company's
exposed credentials

Enter your work email to instantly access a free account
and see your company’s exposed credentials.