Jamf Threat Labs has identified a new and advanced macOS threat that is garnering significant attention in the security community. The malicious code, dubbed DigitStealer, is an infostealer built to sneak under the radar through advanced techniques that make it very difficult to detect. The threat specifically targets macOS and clearly demonstrates that attackers continue to raise their technical level to bypass Apple’s security layers.
The new malicious code macos digit stealer specifically targets macOS users and uses advanced methods that make the discovery difficult for traditional security solutions.

The discovery of DigitStealer
The discovery was made when Jamf Threat Labs analyzed a file that pretended to be a legitimate macOS tool called DynamicLake. The fake application imitated the real macOS tool and was completely invisible to all antivirus engines on VirusTotal at the time of analysis. This shows how quickly threats evolve and how difficult it is for organizations to rely solely on traditional solutions.
An advanced infostealer with a modular attack structure
DigitStealer falls into the infostealer category, meaning its primary purpose is to collect sensitive information from the user's device. This type of code has increased dramatically in the past year and is becoming increasingly complex. DigitStealer uses multiple layers of technical methods to avoid detected while attempting to bypass security features such as macOS Gatekeeper and other built-in protection mechanisms.
A key part of the threat's effectiveness is that it is modular and divided into different stages. Each stage performs checks that determine whether or not to activate malicious code. For example, DigitStealer specific hardware checks that can determine whether the code is running on a physical computer or in an analysis environment. If the program detects signs of a sandbox or virtual environment, it may refrain from activating, making analysis significantly more difficult.

Threat actors are becoming more sophisticated
Pontus Nord at Jamf describes the development clearly.
”"We see that threat actors are becoming increasingly skilled at blending in, hiding their tracks, and exploiting legitimate services and tools to spread malicious code," says Pontus Nord at Jamf.
This level of sophistication has become more common in the last year where an increasing number of macOS threats use script in memory techniques and legitimate API calls to evade detection. The combination of high technical quality and an ability to mimic legitimate activity means that many organizations do not discover the breach until the damage is already done.

In-memory attacks create major challenges
One of the most problematic features of DigitStealer is that parts of the attack run entirely in memory. This means that the malicious code is not written to the hard drive, which means that traditional signature-based antivirus solutions makes it very difficult to identify the threat. Attacks that operate only in memory make it necessary for companies to work with behavioral-based monitoring that can detect anomalies in real time. Behavioral data such as unusual processes, unexpected network connections, and unauthorized access attempts are becoming increasingly important in catching these types of sophisticated threats.
macOS increasingly attractive to cybercriminals
DigitStealer also confirms a broader trend where macOS has become a more attractive platform for cybercriminals. Companies that previously focused almost exclusively on Windows environments are now finding that attackers are prioritizing macOS users as the security level on Windows increases. As more creators, developers, and business users work on Macs, the value of stealing data from these devices increases.

Recommendations from Jamf
Jamf therefore highlights a number of recommendations to strengthen defense capabilities. Organizations should first ensure that advanced threat controls and blockers are enabled in their security solutions. Tools that rely solely on signatures or simple heuristics will not be enough against threats like DigitStealer. Companies are also urged to be extra cautious with software downloaded from unknown or unofficial sources. Social engineering and counterfeit apps are a common method of spreading this type of code.
Companies should also work with a combination of prevention protection and behavioral analytics. Warehouse protection is still relevant but needs to be complemented by real-time monitoring and analytics engines that can detect subtle signs of intrusion. This is especially true in environments where users have administrator rights or install third-party tools that are not through centrally approved channels.
The threat posed by DigitStealer is a clear example of how macOS environments can no longer be considered less vulnerable. Attackers are now investing significant resources in developing specialized code for the Apple ecosystem, making it important for organizations to address macOS with the same security requirements as Windows and Linux.








