New macOS Infinity Stealer uses Nuitka Python payload and ClickFix
2026-03-30T08:51:50Z•1092dd624f1e249be7b7ac1ac30cf964dcac1dfd4ae7073d06e23ffd5e75ae90
applebig-ipcisacitrixclickfixcve-2025-53521cve-2026-3055darksworddata-breacheuropean-commissionf5handalainfinity-stealeriosknown-exploited-vulnerabilitiesmacosmalwarenetscalernuitkaphishingshinyhuntersta446
What happened
Multiple high-risk developments: attackers are actively probing a critical Citrix NetScaler memory-overread flaw (CVE-2026-3055, CVSS 9.3). Separately, CISA added an F5 BIG-IP AMP vulnerability (CVE-2025-53521, CVSS 9.8) to its Known Exploited Vulnerabilities catalog. Apple is pushing lock‑screen warnings about active web-based exploits against unpatched iPhones/iPads while Russia‑linked APT TA446 is using the DarkSword iOS exploit kit in targeted phishing to compromise iPhones. A new macOS infostealer named “Infinity Stealer” uses a Nuitka‑compiled Python payload and spreads via ClickFix fake
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 1092dd624f1e249be7b7ac1ac30cf964dcac1dfd4ae7073d06e23ffd5e75ae90
- Enrichment time
- 2026-03-30T08:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.