logo

MonetaStealer Malware Powered with AI Code Attacking macOS Users in the Wild

ID: e0698c79-3dbc-50bf-a15a-4fb113a584e8

STIX ID: report--e0698c79-3dbc-50bf-a15a-4fb113a584e8

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-01-15

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

MonetaStealer is a newly discovered macOS information‑stealer first identified on 2026-01-06 that disguises itself as a Windows executable and embeds a PyInstaller-packed Python payload (portfolio_app.pyc). It targets Chrome data (using Keychain access to retrieve the master key and copying SQLite DBs to bypass locks), cookies filtered for financial/crypto hosts, browsing history, cryptocurrency wallet data, SSH keys, Wi‑Fi credentials and financial documents, and exfiltrates collected data through a Telegram bot (b746_mac_collector_bot, ID 8384579537); the sample had zero VirusTotal detections and contains ML-generated code and Russian-language comments, suggesting early-stage development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.