Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Levi Strauss Data Breach Exposes Customer and Employee Data
August 8, 2026
OpenAI Pauses Astra Model Development to Assess Cybersecurity Risks
August 8, 2026
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Home/Threats/Weaponized DMG Files Target macOS Users with Infostealer Malware
Threats

Weaponized DMG Files Target macOS Users with Infostealer Malware

Key Takeaways Threat actors are actively leveraging weaponized DMG files to distribute infostealer malware, specifically targeting macOS users. These attacks rely heavily on social engineering...

Emy Elsamnoudy
Emy Elsamnoudy
June 11, 2026 4 Min Read
47 0

Key Takeaways

  • Threat actors are actively leveraging weaponized DMG files to distribute infostealer malware, specifically targeting macOS users.
  • These attacks rely heavily on social engineering through fake software installers, designed to bypass Apple’s built-in security mechanisms.
  • The infostealers are designed for rapid data exfiltration, collecting credentials, browser data, authentication tokens, and cryptocurrency wallet information without establishing persistence.
  • Over 65% of new macOS malware in 2025 was classified as infostealers, indicating a significant shift in threat actor focus towards Apple environments.
  • Effective detection requires proactive monitoring at the disk image mounting stage, rather than waiting for malware execution.

Cybersecurity researchers have identified a troubling surge in attacks against macOS users, with threat actors deploying weaponized Disk Image (DMG) files to deliver potent infostealer malware. This sophisticated tactic directly challenges the long-held perception that Apple’s operating system offers inherent immunity to cyber threats, underscoring a significant evolution in the threat landscape.

Table Of Content

  • Key Takeaways
  • The “Smash-and-Grab” Infostealer Approach
  • Weaponized DMG Files: A Preferred Delivery Method
  • What You Should Do

These campaigns are characterized by their rapid execution and reliance on deceptive software installers. Attackers meticulously craft these fake installers to mimic legitimate applications, effectively tricking users into granting access and bypassing critical security prompts without suspicion. The speed and effectiveness of these operations position them among the most urgent threats currently facing Mac users.

For decades, many macOS users operated under the assumption that their systems were secure by default. This premise is increasingly outdated. In 2025 alone, infostealers accounted for more than 65% of newly reported macOS malware, signaling that threat actors now view Apple environments as high-value targets. The objective is clear: harvest sensitive data including credentials, browser cookies, authentication tokens, and cryptocurrency wallet information.

The “Smash-and-Grab” Infostealer Approach

A distinguishing feature of these infostealers is their swift operational tempo. Unlike traditional malware that seeks to establish persistence on a system through reboots, these threats forgo such mechanisms entirely. Instead, they execute a “smash-and-grab” operation, rapidly exfiltrating sensitive data to a remote server before the victim can detect the compromise.

Analysts at Huntress detailed this pattern in a report shared with Cyber Security News (CSN), highlighting that attackers have almost entirely shifted their focus to social engineering the initial installation phase. Because the malware does not need to persist, the critical vulnerability lies in this first interaction. Attackers heavily invest in making their fake installers indistinguishable from genuine ones, complete with authentic branding and explicit instructions designed to guide users past Apple’s native security features.

Weaponized DMG Files: A Preferred Delivery Method

The deliberate choice of DMG as a delivery format is strategic. Compared to package (.pkg) files, disk images are subject to less rigorous signing requirements and face reduced scrutiny from macOS security checks. When a user double-clicks a DMG, macOS mounts it as a virtual drive in the /Volumes directory, initially isolating its contents. However, this isolation becomes irrelevant once the attacker successfully manipulates the user into cooperating with the malicious installation.

A standard, legitimate DMG file typically presents a clear “drag-to-Applications” prompt. Malicious counterparts appear identical but embed instructions within the background image of the folder window, instructing users on how to override Gatekeeper, Apple’s built-in mechanism for verifying trusted software. These subtle, embedded instructions are often overlooked as suspicious by unsuspecting users. This technique has been observed across several infostealer families, including AMOS, Poseidon, Odyssey, and MacSync.

Attackers have also developed variations of this social engineering approach. In some instances, bypass instructions are directly encoded into the filename itself, such as “Drag to Terminal.” Furthermore, piracy websites frequently distribute “cracked” software, conditioning users to disregard security warnings as normal behavior associated with installing unofficial applications.

What You Should Do

  • Exercise Extreme Caution with Downloads: Only download software from official vendor websites or the Apple App Store. Avoid third-party sites, torrents, or unofficial forums, especially those offering “cracked” or free versions of paid software.
  • Scrutinize Installer Prompts: Be highly suspicious of any installer that instructs you to drag a file to the Terminal, modify System Settings to allow “unknown” software, or disable security features like Gatekeeper. Legitimate applications rarely require such manual overrides.
  • Enhance Security Awareness: Educate yourself and your team about common social engineering tactics. Understand that even on macOS, vigilance is paramount.
  • Implement Endpoint Detection and Response (EDR): Utilize advanced EDR solutions capable of monitoring disk image mounting events and analyzing installer graphics for suspicious instructions, rather than solely relying on post-execution detection.
  • Regularly Back Up Data: Maintain frequent backups of critical data to an offline or cloud storage solution to mitigate the impact of data exfiltration.
  • Enable Multi-Factor Authentication (MFA): Implement MFA wherever possible, especially for email, cloud services, and financial accounts. This adds a crucial layer of security even if credentials are stolen.
  • Keep Software Updated: Ensure your macOS operating system and all applications are kept up to date to benefit from the latest security patches.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Cybercriminals Exploit Residential Proxies to Mask Attacks

Next Post

BLUERABBIT Backdoor Encrypts Files, Wipes Disks on Windows Systems

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Zapscape KVM Vulnerability CVE-2026-64561 Allows Guest-to-Host Escape
August 7, 2026
Chrome 101 Patches 41 Vulnerabilities, 6 Critical Memory Bugs
August 7, 2026
Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us