logo

“Matryoshka” Malware: New macOS Attack Hides Inside “Russian Dolls” of Obfuscation

ID: 90adf904-1e52-538f-898c-6c714e547e63

STIX ID: report--90adf904-1e52-538f-898c-6c714e547e63

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-23

Author: Ddos

...
...

Matryoshka is a macOS-targeting social-engineering campaign that lures cryptocurrency users from typo-squatted sites through a Traffic Distribution System, instructs victims to paste a 'fix' command into Terminal, and installs a heavily obfuscated, in-memory stealer. The malware employs nested obfuscation and API-gated communications to evade detection, harvests browser data, and surgically tampers with or replaces wallet application components (notably Ledger Live and Trezor Suite) to exfiltrate funds while presenting fake error messages to delay discovery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.