Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Government Directive Blocks Anthropic Fable 5 & Mythos Access
June 13, 2026
Fancy Bear Abuses EdgeRouters & Cloud for Stealthy
June 12, 2026
Hackers Abuse NinjaOne RMM to Bypass Malware Legitimate Software
June 12, 2026
Home/Threats/Hackers Target macOS Users with Weaponized DMG Inf
Threats

Hackers Target macOS Users with Weaponized DMG Inf

Threat actors are actively deploying weaponized DMG files to infect macOS systems with infostealer malware, directly challenging the persistent myth that Apple devices are immune to cyber threats....

Emy Elsamnoudy
Emy Elsamnoudy
June 11, 2026 4 Min Read
5 0

Threat actors are actively deploying weaponized DMG files to infect macOS systems with infostealer malware, directly challenging the persistent myth that Apple devices are immune to cyber threats. This emerging tactic, detailed in a These attacks rely on fake software installers disguised as legitimate apps, tricking users into handing over access without raising any alarm.

The speed of these campaigns has made them one of the most pressing threats to Mac users today. For decades, many Mac users believed their systems were safe by default.

That assumption no longer holds. In 2025, over 65% of newly reported macOS malware was classified as infostealers, a sign that attackers now treat Apple environments as high-value targets. Credentials, browser cookies, authentication tokens, and crypto wallets are all fair game.

What sets these infostealers apart is how fast they move. They skip persistence entirely and do not plant themselves on the machine to survive a reboot.

Instead, they run a smash-and-grab, pulling sensitive data and sending it off to a remote server before the victim notices.

Analysts at Huntress said in a report shared with Cyber Security News (CSN) that they identified this pattern and the attackers have shifted focus almost entirely to social engineering the installation moment.

Because the malware does not need to linger, the real battleground is that first installation step. Attackers invest heavily in making fake installers look exactly like the real thing, complete with branded graphics and instructions guiding victims to bypass Apple’s built-in protections.

The infection chain typically starts in a web browser, where users land on poisoned search results or piracy forums. One wrong click is all it takes.

Hackers Use Weaponized DMG Files

The choice of DMG as a delivery format is deliberate. Compared to package (.pkg) files, disk images require less formal signing and attract far less scrutiny from macOS security checks.

When a user double-clicks a DMG, macOS mounts it as a virtual drive at /Volumes, keeping its contents isolated. That isolation means very little once the attacker has the user’s cooperation.

SEO poisoning leads to a deceptive installer of a fake Arc browser (Source - Huntress)
SEO poisoning leads to a deceptive installer of a fake Arc browser (Source – Huntress)

A legitimate DMG shows a familiar drag-to-Applications prompt. A malicious one looks identical but includes instructions on how to override Gatekeeper, Apple’s tool for verifying trusted software.

Those instructions are embedded in the background image of the folder window, easy to miss as suspicious. This technique is used by infostealer families including AMOS, Poseidon, Odyssey, and MacSync.

Infostealer social engineering the user to override Gatekeeper (Source - Huntress)
Infostealer social engineering the user to override Gatekeeper (Source – Huntress)

Attackers have also found variations on this approach. In some cases, bypass instructions are encoded directly into the filename itself, such as naming the file “Drag to Terminal”.

Piracy sites distribute software labeled “cracked,” pre-conditioning users to treat all security warnings as normal.

Detection and Recommended Steps

Most endpoint tools wait for malware to execute before flagging anything. By that point, the theft is already done and stolen data is leaving the machine. Catching the attack before the user clicks past the installer is what makes the difference.

The struct and enum of the mount ES event (Source - Huntress)
The struct and enum of the mount ES event (Source – Huntress)

Detection at the mount stage involves monitoring virtual disk images in /Volumes, scanning for hidden .background directories, and reading text from installer graphics using optical character recognition. Fuzzy matching also catches intentional misspellings attackers use to evade keyword filters.

Apple's Vision Framework documentation (Source - Huntress)
Apple’s Vision Framework documentation (Source – Huntress)

When a suspicious installer is flagged, the immediate step is to unmount the disk image and stop any associated processes. If the user has already moved forward, the focus shifts to downstream behavior such as Keychain access or privilege escalation.

The security awareness is a critical line of defense, since the whole attack depends on a human manually approving something they should not.

Users should avoid downloading software from unofficial sources or cracked forums. Any installer asking you to drag a file into Terminal or approve unknown software in System Settings is a red flag worth taking seriously.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Hackers Use Residential Proxies to Hide Malicious Activity

Next Post

BLUERABBIT Backdoor Encrypts Files, W Hackers Wipe

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Google Sues Chinese Cybercrime for Gemini AI Cyberattacks
June 12, 2026
Arch Linux AUR Supply Chain Attack Deploys Infostealers
June 12, 2026
Critical LangGraph Vulnerability Gives Attackers Full Server Control
June 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us