logo

Fake Windows Executables Target macOS: Inside the “MonetaStealer” Discovery

ID: e167ae48-4c00-54c8-8ff8-b9ad18dc24b6

STIX ID: report--e167ae48-4c00-54c8-8ff8-b9ad18dc24b6

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-20

Date Updated: 2026-04-23

Author: Ddos

...
...

MonetaStealer is a macOS infostealer disguised as a .exe Windows file (Portfolio_Review.exe); it leverages PyInstaller to hide a Python payload (portfolio_app.pyc) and targets Google Chrome credentials, multiple cryptocurrency wallets, seed phrases/private keys, and macOS Keychain/Wi‑Fi credentials, currently showing zero detections and relying on social engineering to prompt user authorization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.