New macOS Malware notnullOSX Targets Crypto Wallets Over $10K
ID: 53501bc2-3009-5f35-a009-79040da082d5
STIX ID: report--53501bc2-3009-5f35-a009-79040da082d5
Feed Name: HackRead
Moonlock Lab discovered notnullOSX, a modular macOS malware first seen on 30 March 2026 active in Vietnam, Taiwan, and Spain, designed to target high-value cryptocurrency holders. Attackers use social engineering (fake protected Google Docs and terminal paste commands) and malicious app distribution (hijacked YouTube promotion, fake WallSpace) to gain Full Disk Access, maintain a backdoor, and deploy a ReplaceApp feature that substitutes legitimate wallet software (Ledger Live, Trezor, desktop wallets) to capture seed phrases and credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
