'Stealers' Are an Increasingly Common Mac Malware - MacRumors
Skip to Content

'Stealers' Are an Increasingly Common Mac Malware

macOS stealers are becoming an increasingly common type of malware on the Mac, according to the 2025 State of Malware report that Malwarebytes shared this week.

macos stealer market share
Most Mac malware has historically been VSearch adware or the Genieo browser hijacker, but more malicious malware is on the rise, and 2024 saw a new wave of information stealing malware hit the Mac.

Stealers are designed to locate credit card information, authentication cookies, cryptocurrency, passwords, and other valuable data that criminals can use to make money.

Malicious apps that steal information are typically installed when a Mac user searches for a legitimate software product and then uses a malicious Google or Bing search ad to download an infested replica version of the software they sought. Attackers are able to deliver targeted ads for malicious software based on location, operating system, software, and search terms.

Atomic Stealer (AMOS), an information stealer that surfaced in 2023, is used regularly, and a version of AMOS referred to as Poseidon has becoming increasingly popular with criminals. Poseidon is advertised as being able to steal cryptocurrency from more than 160 wallets as well as passwords from web browsers and select password managers. Poseidon downloads have masqueraded as legitimate Mac apps like the Arc Browser, tricking unsuspecting Mac users into installing the malware.

Malwarebytes warns that macOS stealers like Poseidon allow criminals to access sensitive resources, steal credentials, and create convincing social engineering attacks.

To avoid this kind of attack, it is important to verify where software is being downloaded from, ensuring that it comes from a legitimate developer and not an imitation website.

Popular Stories

WWDC26 MR Live Coverage Article

WWDC 2026 Apple Event Live Keynote Coverage: iOS 27, Revamped Siri, and More

Monday June 8, 2026 9:15 am PDT by
Apple's Worldwide Developers Conference (WWDC) starts today with the traditional keynote kicking things off at 10:00 a.m. Pacific Time. MacRumors is on hand for the event and we'll be sharing details and our thoughts throughout the day. We're expecting to see a number of software-related announcements today, headlined by a reset on Apple's push into AI that should see a significant overhaul...
Aston Martin CarPlay Ultra Screen

Apple Says CarPlay Ultra is Coming to These Vehicle Brands

Thursday May 21, 2026 11:53 am PDT by
Last year, Apple launched CarPlay Ultra, the long-awaited next-generation version of its CarPlay software system for vehicles. Nearly a year later, CarPlay Ultra is still limited to Aston Martin's latest luxury vehicles, but that should change fairly soon. In May 2025, Apple said many other vehicle brands planned to offer CarPlay Ultra, including Hyundai, Kia, and Genesis. CarPlay Ultra...
macOS Golden Gate Mac

Apple Announces macOS Golden Gate

Monday June 8, 2026 10:19 am PDT by
Apple today announced that macOS 27 is named macOS Golden Gate. Much like Mac OS X Snow Leopard in 2009, Apple said it focused on improving macOS's performance and dozens of underlying technologies this year. Apple says macOS Golden Gate offers quicker AirDrop transfers, faster network file browsing, improved syncing in the Messages app, better Spotlight search suggestions, and other...

Top Rated Comments

Pakaku Avatar
18 months ago

Malicious apps that steal information are typically installed when a Mac user searches for a legitimate software product and then uses a malicious Google or Bing search ad to download an infested replica version of the software they sought. Attackers are able to deliver targeted ads for malicious software based on location, operating system, software, and search terms.
So... just more reasons to use an adblocker. Especially if ad providers aren't going to be responsible about what they show, which has been a problem for far longer.
Score: 21 Votes (Like | Disagree)
Arislan Avatar
18 months ago
So still a social engineered lack of knowledge attack. Got it.
Score: 13 Votes (Like | Disagree)
18 months ago

are typically installed when a Mac user searches for a legitimate software product and then uses a malicious Google or Bing search ad to download an infested replica version of the software they sought
Ain't "side loading" grand?
Score: 12 Votes (Like | Disagree)
18 months ago

This *just* happened to my mom. <facepalm>
My mom doesn’t get admin rights.
Score: 11 Votes (Like | Disagree)
18 months ago

This is why non-nerds should replace their devices when they cease receiving OS version or security updates.

If you're on a Mac that cannot run 2022 macOS 13 Ventura or newer then replace it with any Mac with Apple Silicon.

In 2025 Intel Macs are only suitable for export to poor countries where data security is as valuable as their bank accounts.
Don’t disagree with the first point - non-nerds should definitely replace devices when they cease receiving security updates.

But in 2025, many Intel Macs are still as secure as ever - they still receive OS version and security updates, etc.
Score: 10 Votes (Like | Disagree)
fathergll Avatar
18 months ago

Macs dont get virus
Correct.

Source; Apple


Score: 10 Votes (Like | Disagree)