ClickFix, Malicious DMGs Push notnullOSX to macOS Users
ID: 78f1c8e2-0066-5d89-b1fc-4f0f2ee0e887
STIX ID: report--78f1c8e2-0066-5d89-b1fc-4f0f2ee0e887
Feed Name: GBHackers
This report describes notnullOSX, a Go-based modular macOS stealer actively used in a targeted campaign to extract high-value crypto wallets by tricking victims into running base64-encoded Terminal installers or mounting booby-trapped DMGs. Operators vet targets via an affiliate panel (rejecting wallets < $10k), distribute the malware through cloned sites, YouTube funnels, and ClickFix-style commands, and maintain persistent, TLS-encrypted C2 via Firebase; confirmed detections were observed in Vietnam, Taiwan, and Spain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
