[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fHq4ZK959WtPn8T5b-aU2dI42sQ_H6L5WM_9u-qljvos":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"b7d82a84-e5d3-45fa-afb1-0fe1915b3494","social-engineering-attack-delivers-macos-data-stealer-via-fake-security-prompts","fe7948e8-2c84-40c7-8ea6-6319a8461165","Social Engineering Attack Delivers macOS Data Stealer via Fake Security Prompts","Cybercriminals are exploiting user trust by impersonating legitimate security services like Cloudflare to trick macOS users into executing malicious commands. The Infinity Stealer campaign demonstrates how attackers can weaponize familiar security interfaces to bypass technical controls and convince users to compromise their own systems. Once users paste the malicious curl commands into Terminal, the malware harvests sensitive data including browser credentials, cryptocurrency wallets, and developer secrets. This attack highlights the critical importance of user education and the need for robust data protection measures on endpoints.","**Immediate actions:**\n- Train users to never paste unknown commands into Terminal or command line interfaces\n- Implement endpoint detection and response (EDR) solutions to monitor suspicious process execution\n- Enable macOS Gatekeeper and require signed applications from identified developers\n\n**Long-term improvements:**\n- Establish regular security awareness training focusing on social engineering tactics\n- Deploy application allowlisting to prevent unauthorized executables from running\n- Implement data loss prevention (DLP) solutions to monitor sensitive data exfiltration\n\n**Detection measures:**\n- Monitor network traffic for suspicious HTTP communications to unknown C2 servers\n- Set up alerts for Terminal or shell processes spawned by web browsers\n- Configure logging to track access to sensitive data stores like keychains and browser credential databases",[12,13,14,15,16],"CIS Control 14","CIS Control 13","NIST PR.AT-1","NIST DE.CM-1","NIST PR.DS-1","published","2026-03-28T15:07:11.480317+00:00","2026-03-28T15:07:11.182+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-infinity-stealer-malware-grabs-macos-data-via-clickfix-lures\u002F","new-infinity-stealer-malware-grabs-macos-data-via-clickfix-lures","New Infinity Stealer malware grabs macOS data via ClickFix lures",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":32,"name":33,"slug":34,"description":35,"color":36},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]