logo

“Say My Name”: How MioLab is building MacOS Stealer Empire

ID: 54791767-8f17-5511-91e9-ca3a978032b0

STIX ID: report--54791767-8f17-5511-91e9-ca3a978032b0

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
78/100

Date Published: 2026-03-20

Date Updated: 2026-04-28

Author: Mark Tsipershtein and Evgeny Ananin

...
...

MioLab (aka Nova) is a commercially sold macOS infostealer MaaS actively distributed via targeted malvertising and a ClickFix-style execution chain; it supports Intel and Apple Silicon, uses runtime string obfuscation and FUD techniques, harvests browser data, Keychain items, Apple Notes, messaging sessions, desktop wallet files and actively targets hardware wallets (Ledger/Trezor) to exfiltrate seed phrases. The platform includes a user-friendly web panel, builder tools (DMG/Unix), API access, per-build proxying, and modular plugins for crypto theft, with observed active infrastructure (domains, IPs, C2 endpoints), IoCs, and operational overlap with Web3 phishing campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.