Last Update: 09/22/2026 at 11:34 PM EST

macOS Infostealers Exploit Fake Prompts

Coverage from BleepingComputer and others

macOS Infostealers Exploit Fake Prompts topic image

Multiple macOS infostealer campaigns are using fake Apple or security prompts, ClickFix-style lures, and trusted tools such as Terminal and Script Editor to persuade users to run malware or disclose their passwords.

The malware targets Keychain credentials, browser data, password managers, files, and cryptocurrency wallets, with some variants adding persistence and remote-control capabilities. The activity shows a consistent shift toward social engineering and abuse of legitimate macOS workflows rather than reliance on software exploits alone.

Looking Back
111 Day Timeline
Mar 28Apr 18May 9May 30Jun 20Jul 11
History
07/23/2026

The story is now framed more tightly around fake macOS system prompts and trusted built-in tools as the main delivery mechanism, with less emphasis on specific malware names and more on the breadth of credential theft and persistence techniques. The current version also adds that some variants go beyond theft by loading payloads or opening reverse shells.

07/22/2026

The story broadens from a general macOS infostealer pattern into a more specific, multi-family campaign set with clearer delivery methods, persistence behavior, and one quantified impact report. The current version also adds several named actors and strengthens the case that these operations combine credential theft with durable remote access.

All Articles5 articles
Additional5 articles · CI Score below 45
BleepingComputer / Bill Toulas
7/16/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Bill Toulas
7/13/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Bill Toulas
5/18/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Bill Toulas
4/8/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Bill Toulas
3/28/2026 • Cybersecurity (Privacy-Relevant) • General