logo

ClickFix, Malicious DMGs Push notnullOSX to macOS Users

ID: 78f1c8e2-0066-5d89-b1fc-4f0f2ee0e887

STIX ID: report--78f1c8e2-0066-5d89-b1fc-4f0f2ee0e887

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

This report describes notnullOSX, a Go-based modular macOS stealer actively used in a targeted campaign to extract high-value crypto wallets by tricking victims into running base64-encoded Terminal installers or mounting booby-trapped DMGs. Operators vet targets via an affiliate panel (rejecting wallets < $10k), distribute the malware through cloned sites, YouTube funnels, and ClickFix-style commands, and maintain persistent, TLS-encrypted C2 via Firebase; confirmed detections were observed in Vietnam, Taiwan, and Spain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.