logo

MioLab MacOS Stealer Expands With ClickFix, Wallet Theft, Team APIs

ID: 5ec0a82c-336c-5b3e-99ee-e9b9ba5f6e85

STIX ID: report--5ec0a82c-336c-5b3e-99ee-e9b9ba5f6e85

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-23

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

MioLab (aka Nova) is a professionally marketed macOS infostealer offered as Malware‑as‑a‑Service that targets browsers, Keychain, Apple Notes, messaging apps, and over 200 crypto wallet extensions as well as desktop wallets and hardware‑wallet companion apps to harvest credentials and exfiltrate data; it uses obfuscation, social‑engineering ClickFix delivery, and a polished web panel with proxy and builder infrastructure to scale theft and evade takedowns. The report outlines attack chain, technical capabilities, infrastructure reuse (including Cloudflare‑fronted domains and bulletproof hosting), and practical mitigations such as hardening Terminal policies, detecting abuse of dscl/osascript/system_profiler/curl, blocking known C2 ranges, enforcing code signing, and user education.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.