Hackers Abuse Fake Wallpaper App and YouTube Channel to Spread notnullOSX Malware
ID: cad2bef5-f881-5a1f-b5c9-c4ebd580a5fc
STIX ID: report--cad2bef5-f881-5a1f-b5c9-c4ebd580a5fc
Feed Name: cybersecurityNews.com
notnullOSX is a sophisticated macOS stealer (discovered March 30, 2026) designed to drain cryptocurrency holdings above $10,000. Operators use targeted social-engineering (fake protected Google Docs, a faux WallSpace live-wallpaper DMG, and a hijacked decade-old YouTube channel) to trick victims into running Terminal commands or installing a disk image, then escalate privileges by having victims grant Full Disk Access. The multi-architecture Mach-O implant exfiltrates iMessages, Apple Notes, Safari cookies and passwords, Telegram sessions, multiple cryptocurrency wallets (Bitcoin Core, Exodus, Electrum), and includes a ReplaceApp module that swaps legitimate wallet apps (e.g., Ledger Live) with malicious clones to capture seed phrases; it maintains remote connectivity for follow-up actions. Moonlock Lab telemetry shows multi-region detections (Vietnam, Taiwan, Spain), low detection rates on VirusTotal, and identified IOCs and behaviors (domains, Mach-O download patterns, xattr quarantine removal, LaunchAgent persistence); recommended mitigations include avoiding pasted Terminal commands, verifying Full Disk Access requests, auditing LaunchAgents, blocking listed outbound domains, and alerting on quarantine-clearing and short-lived Mach-O activity in /tmp.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
