Home Cyber Security News Emergence of a macOS Infostealer Within Illicit Online Marketplaces

Emergence of a macOS Infostealer Within Illicit Online Marketplaces

0
macOS infostealer

A new macOS-focused information stealer, dubbed “MioLab MacOS,” has surfaced on underground cybercrime forums, advertising a malware-as-a-service (MaaS) subscription targeting Apple systems.

The malware’s alleged capabilities suggest a growing shift in the infostealer landscape toward macOS users, who are traditionally considered less targeted than Windows users.

A New Threat in the macOS Malware Ecosystem

According to underground advertisements circulating across cybercrime channels, MioLab markets its tool as a “resident macOS infostealer” with an integrated web-based management panel and individual configuration options.

Its developer claims that subscribers can manage large-scale infection campaigns through a dashboard that handles log collection, Telegram bot integration, and data exfiltration workflows.

Once deployed, the infostealer reportedly extracts a broad range of sensitive information from victims’ systems, including cookies, stored passwords, browsing history, and autofill data from Chromium and Gecko-based browsers. 

In addition, MioLab allegedly captures Google authentication tokens and targets more than 200 cryptocurrency wallet extensions, including MetaMask, Trust Wallet, and Phantom, indicating a strong focus on digital asset theft.

The malware’s code reportedly includes modules for stealing credentials from more than 15 password managers, including popular solutions such as LastPass, 1Password, and Dashlane.

Beyond browser and password data, MioLab also claims to decrypt the macOS Keychain, copy Apple Notes, and apply a custom FileGrabber configuration to capture key files, particularly those linked to cold wallets (.dat, .key, and .keys).

Commercialization and Market Positioning

The actor behind MioLab is positioning the stealer as a premium rental service. Advertisements list a US$750 monthly subscription fee, with optional paid modules priced at US$500 for Ledger and Trezor hardware wallet targeting.

The developer also promotes discounted “percentage deals” for larger criminal operators seeking long-term access or broader distribution capabilities.

While these features remain unverified and based on seller claims, the emergence of a dedicated macOS infostealer illustrates a significant shift in threat actor focus.

Historically, macOS-targeting malware accounted for a small share of info-stealer activity, while most cybercriminal operations focused on Windows-based malware such as RedLine, Raccoon, and LummaC2.

The release of MioLab, however, suggests that underground developers are now investing in cross-platform tools to capitalize on the growing macOS user base across personal and enterprise environments.

Security researchers warn that this trend could lead to increased attacks on macOS devices with browser data, keychains, and cryptocurrency assets as primary targets.

Organizations and users are advised to update endpoint protection, monitor for suspicious macOS processes, and restrict storing credentials in browsers or password files to minimize exposure.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version