started · updated
MacOS Infostealer Surge and WhatsApp Travel Phishing Spike
Researchers report that infostealers now account for more than 65% of all new macOS malware. The malicious code targets Apple’s Keychain, browser passwords and crypto‑wallet extensions such as MetaMask, Phantom and Coinbase Wallet. Distribution occurs mainly through .dmg files, with attackers using fake developer certificates or social‑engineering tricks to bypass Gatekeeper. Active campaigns include AMOS, Odyssey Stealer (masquerading as a ChatGPT app) and FlutterBridge, a dual‑purpose adware.
A North‑Korean hacking group, Sapphire Sleet (BlueNoroff), carried out a large supply‑chain attack on over 140 npm packages, inserting code that infects Windows, Linux and macOS systems and harvests data from 166 crypto‑wallet extensions. In a related breach, 124 million passwords and 56 million email addresses harvested from infostealer logs were added to the Have I Been Pwned database.
Separately, Bitdefender Labs identified a surge in vacation‑related phishing that exploits WhatsApp as the contact channel. Attackers use genuine booking information – hotel names, travel dates and reservation numbers – to craft believable messages in Germany, France, the UK, the Netherlands and other countries. Victims are redirected to counterfeit booking sites that harvest credit‑card and personal data. The campaigns are professionally organized, frequently changing domains and employing valid TLS certificates to appear legitimate.