New macOS Infinity Stealer uses Nuitka Python payload and ClickFix

2026-03-30T08:51:50Z1092dd624f1e249be7b7ac1ac30cf964dcac1dfd4ae7073d06e23ffd5e75ae90
applebig-ipcisacitrixclickfixcve-2025-53521cve-2026-3055darksworddata-breacheuropean-commissionf5handalainfinity-stealeriosknown-exploited-vulnerabilitiesmacosmalwarenetscalernuitkaphishingshinyhuntersta446

What happened

Multiple high-risk developments: attackers are actively probing a critical Citrix NetScaler memory-overread flaw (CVE-2026-3055, CVSS 9.3). Separately, CISA added an F5 BIG-IP AMP vulnerability (CVE-2025-53521, CVSS 9.8) to its Known Exploited Vulnerabilities catalog. Apple is pushing lock‑screen warnings about active web-based exploits against unpatched iPhones/iPads while Russia‑linked APT TA446 is using the DarkSword iOS exploit kit in targeted phishing to compromise iPhones. A new macOS infostealer named “Infinity Stealer” uses a Nuitka‑compiled Python payload and spreads via ClickFix fake

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
1092dd624f1e249be7b7ac1ac30cf964dcac1dfd4ae7073d06e23ffd5e75ae90
Enrichment time
2026-03-30T08:51:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · New macOS Infinity Stealer uses Nuitka Python payload and ClickFix · Baitaphish