macOS Infostealers That Actively Involve in Attacks XProtect

The rise in infostealers targeting macOS since 2023 has prompted Apple to update their XProtect antivirus signature databases to prevent such attacks. Currently active infostealers evading Apple’s protections include KeySteal, Atomic InfoStealer, and CherryPie. These infostealers are increasingly sophisticated, using evasion techniques and various distribution methods. Despite Apple’s updates, threat actors continue to find ways around detection and prevention measures.

