logo

Hackers Use ClickFix and Malicious DMG Files to Deliver notnullOSX on macOS

ID: d7856003-2f62-50c1-af64-d2342fcff7ef

STIX ID: report--d7856003-2f62-50c1-af64-d2342fcff7ef

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A targeted macOS info-stealer called notnullOSX, written in Go and sold via an affiliate model, is being used to compromise high-value cryptocurrency holders by tricking victims into granting Full Disk Access or running terminal commands; it uses modular theft binaries (iMessageGrab, CryptoWalletsGrab, ReplaceApp, etc.), maintains a persistent WebSocket connection to a Firebase C2, and has confirmed detections across multiple countries — defenders are advised to block known C2 domains, alert on unexpected Full Disk Access grants, and monitor /tmp and LaunchAgents for staged Mach-O binaries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.