The High-Stakes Return of 0xFFF: ‘notnullOSX’ Stealer Targets macOS Crypto Whales
ID: 14836e16-30dd-5ad0-88c6-4b4bda0a7da9
STIX ID: report--14836e16-30dd-5ad0-88c6-4b4bda0a7da9
Feed Name: securityonline.info
notnullOSX is a new, modular macOS stealer attributed to an actor known as alh1mik (formerly 0xFFF). First seen on 2026-03-30, it is distributed via a ClickFix social-engineering flow and malicious DMG files, uses WebSocket-based live C2 to receive modules and updates, and contains a ReplaceApp component specifically designed to swap legitimate hardware-wallet manager apps with trojanized clones. Operators actively profile high-value crypto targets (threshold > $10,000), with initial detections reported in Vietnam, Taiwan, and Spain, indicating a professionalized, persistent threat to macOS crypto users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
