MioLab MacOS Stealer Expands With ClickFix, Wallet Theft, Team APIs
ID: 5ec0a82c-336c-5b3e-99ee-e9b9ba5f6e85
STIX ID: report--5ec0a82c-336c-5b3e-99ee-e9b9ba5f6e85
Feed Name: GBHackers
MioLab (aka Nova) is a professionally marketed macOS infostealer offered as Malware‑as‑a‑Service that targets browsers, Keychain, Apple Notes, messaging apps, and over 200 crypto wallet extensions as well as desktop wallets and hardware‑wallet companion apps to harvest credentials and exfiltrate data; it uses obfuscation, social‑engineering ClickFix delivery, and a polished web panel with proxy and builder infrastructure to scale theft and evade takedowns. The report outlines attack chain, technical capabilities, infrastructure reuse (including Cloudflare‑fronted domains and bulletproof hosting), and practical mitigations such as hardening Terminal policies, detecting abuse of dscl/osascript/system_profiler/curl, blocking known C2 ranges, enforcing code signing, and user education.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
