logo

New macOS Malware notnullOSX Targets Crypto Wallets Over $10K

ID: 53501bc2-3009-5f35-a009-79040da082d5

STIX ID: report--53501bc2-3009-5f35-a009-79040da082d5

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Moonlock Lab discovered notnullOSX, a modular macOS malware first seen on 30 March 2026 active in Vietnam, Taiwan, and Spain, designed to target high-value cryptocurrency holders. Attackers use social engineering (fake protected Google Docs and terminal paste commands) and malicious app distribution (hijacked YouTube promotion, fake WallSpace) to gain Full Disk Access, maintain a backdoor, and deploy a ReplaceApp feature that substitutes legitimate wallet software (Ledger Live, Trezor, desktop wallets) to capture seed phrases and credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.