MacOS Stealer MioLab Adds ClickFix Delivery, Wallet Theft and Team API Tools
ID: a66cfebb-ae46-5b11-9d08-cb0901dff25c
STIX ID: report--a66cfebb-ae46-5b11-9d08-cb0901dff25c
Feed Name: cybersecurityNews.com
A new, actively marketed macOS infostealer called MioLab (Nova) is being sold as Malware‑as‑a‑Service and targets Apple devices across Intel and Apple Silicon. The platform offers a web admin panel, programmatic Team API, Telegram integration for affiliates, and a lightweight Mach‑O payload that evades basic AV; capabilities include browser credential theft, crypto wallet draining, Apple Notes decryption, and a premium module to extract BIP39 recovery seeds from hardware wallets. Operators distribute the malware via a ClickFix terminal‑command social engineering chain and malvertising using cloned developer documentation (e.g., Claude Code), and they host infrastructure on bulletproof providers; the report includes IOCs, defensive guidance, and recommended monitoring of sensitive macOS utilities and suspicious network activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
