MonetaStealer Malware Powered with AI Code Attacking macOS Users in the Wild
ID: e0698c79-3dbc-50bf-a15a-4fb113a584e8
STIX ID: report--e0698c79-3dbc-50bf-a15a-4fb113a584e8
Feed Name: cybersecurityNews.com
MonetaStealer is a newly discovered macOS information‑stealer first identified on 2026-01-06 that disguises itself as a Windows executable and embeds a PyInstaller-packed Python payload (portfolio_app.pyc). It targets Chrome data (using Keychain access to retrieve the master key and copying SQLite DBs to bypass locks), cookies filtered for financial/crypto hosts, browsing history, cryptocurrency wallet data, SSH keys, Wi‑Fi credentials and financial documents, and exfiltrates collected data through a Telegram bot (b746_mac_collector_bot, ID 8384579537); the sample had zero VirusTotal detections and contains ML-generated code and Russian-language comments, suggesting early-stage development.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
