“Say My Name”: How MioLab is building MacOS Stealer Empire
ID: 54791767-8f17-5511-91e9-ca3a978032b0
STIX ID: report--54791767-8f17-5511-91e9-ca3a978032b0
Feed Name: LevelBlue SpiderLabs Blog
MioLab (aka Nova) is a commercially sold macOS infostealer MaaS actively distributed via targeted malvertising and a ClickFix-style execution chain; it supports Intel and Apple Silicon, uses runtime string obfuscation and FUD techniques, harvests browser data, Keychain items, Apple Notes, messaging sessions, desktop wallet files and actively targets hardware wallets (Ledger/Trezor) to exfiltrate seed phrases. The platform includes a user-friendly web panel, builder tools (DMG/Unix), API access, per-build proxying, and modular plugins for crypto theft, with observed active infrastructure (domains, IPs, C2 endpoints), IoCs, and operational overlap with Web3 phishing campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
