Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Threat Actors Advertising ‘MioLab MacOS’ Infostealer on an Underground Forum

Threat Actors Advertising ‘MioLab MacOS’ Infostealer on an Underground Forum

Posted on December 15, 2025December 15, 2025 By CWS

A brand new malware risk concentrating on macOS customers has emerged on underground cybercrime boards, with risk actors advertising and marketing a complicated information-stealing software known as “MioLab MacOS.”

This resident infostealer comes outfitted with a web-based management panel and customizable settings, making it a pretty choice for cybercriminals trying to compromise Apple units.

The malware is being marketed as a subscription service, highlighting the rising development of Malware-as-a-Service (MaaS) operations that decrease the entry barrier for attackers.

The vendor claims that MioLab MacOS can extract delicate info from browsers, password managers, cryptocurrency wallets, and even Apple’s Keychain system.

With help for over 200 crypto pockets extensions, together with MetaMask and Belief Pockets, the malware poses a severe danger to digital asset holders.

Moreover, it targets greater than 15 password administration purposes, resembling LastPass, placing saved credentials at vital danger.

The malware additionally encompasses a FileGrabber with customized filtering guidelines and might acquire recordsdata with particular extensions like .dat, .key, and .keys from over 50 chilly pockets purposes.

KrakenLabs researchers recognized this risk circulating on underground boards the place the developer actively promotes the subscription mannequin.

🚨 MioLab advertises a macOS stealer subscription#MioLab is advertising and marketing “MioLab MacOS” as a resident macOS infostealer with an online panel and “particular person configuration” on an underground discussion board.🛠️Claimed capabilities:• 🍪 Steal cookies, passwords, historical past, autofill• 🔑 Seize… pic.twitter.com/zV37HA4Zea— KrakenLabs (@KrakenLabs_Team) December 15, 2025

The pricing construction features a month-to-month subscription payment of $750 USD and an extra one-time cost of $500 USD for specialised Ledger and Trezor {hardware} pockets modules.

The vendor additionally presents percentage-based offers for high-volume cybercriminals, indicating a business-oriented strategy to malware distribution.

The malware’s knowledge assortment capabilities prolong past monetary info. It could steal browser cookies, passwords, shopping historical past, and autofill knowledge from each Chromium and Gecko-based browsers.

Discussion board publish (Supply – X)

MioLab MacOS additionally captures Google authentication tokens, enabling attackers to bypass safety measures and achieve persistent entry to sufferer accounts.

Moreover, it performs full gadget profiling to assemble system info and might extract content material from Apple Notes, probably revealing private and business-related info.

Information Exfiltration and Command Infrastructure

MioLab MacOS makes use of Telegram bot integration for stolen knowledge transmission, permitting attackers to obtain notifications and handle compromised info by an encrypted messaging platform.

The malware encompasses a centralized net panel that gives risk actors with log administration capabilities and real-time monitoring of contaminated units.

This infrastructure permits operators to arrange stolen credentials, monetary knowledge, and private info effectively.

The mixture of Telegram exfiltration and web-based administration creates a dependable command and management system that helps attackers preserve operational safety whereas managing a number of victims concurrently.

Comply with us on Google Information, LinkedIn, and X to Get Extra Immediate Updates, Set CSN as a Most popular Supply in Google.

Cyber Security News Tags:Actors, Advertising, Forum, InfoStealer, macOS, MioLab, Threat, Underground

Post navigation

Previous Post: New Android Malware Frogblight Mimics as Official Government Websites to Collect SMS and Device Details
Next Post: JumpCloud Remote Assist for Windows Agent Flaw Let Attackers Escalate Privilege

Related Posts

CrystalX Malware-as-a-Service on Telegram Exposed CrystalX Malware-as-a-Service on Telegram Exposed Cyber Security News
DuckDuckGo Introduces Built-In YouTube Ad Blocking DuckDuckGo Introduces Built-In YouTube Ad Blocking Cyber Security News
W3 Total Cache Command Injection Vulnerability Exposes 1 Million WordPress Sites to RCE Attacks W3 Total Cache Command Injection Vulnerability Exposes 1 Million WordPress Sites to RCE Attacks Cyber Security News
Free WormGPT Variant Leveraging DeepSeek, Gemini, and Kimi-K2 AI Models Free WormGPT Variant Leveraging DeepSeek, Gemini, and Kimi-K2 AI Models Cyber Security News
Tech Giants Under Fire for Ignoring Privacy Opt-Outs Tech Giants Under Fire for Ignoring Privacy Opt-Outs Cyber Security News
Threat Actors May Abuse VS Code Extensions to Deploy Ransomware and Use GitHub as C2 Server Threat Actors May Abuse VS Code Extensions to Deploy Ransomware and Use GitHub as C2 Server Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Cisco Firewall Vulnerability Urges Immediate Action
  • SharePoint Vulnerability Abused After PoC Emerges
  • WordPress Urges Update to Fix Critical RCE Vulnerability
  • Hundreds of Fake VPN Extensions Divert Browser Traffic
  • Critical VMware vCenter Vulnerability Exploited by Hackers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Cisco Firewall Vulnerability Urges Immediate Action
  • SharePoint Vulnerability Abused After PoC Emerges
  • WordPress Urges Update to Fix Critical RCE Vulnerability
  • Hundreds of Fake VPN Extensions Divert Browser Traffic
  • Critical VMware vCenter Vulnerability Exploited by Hackers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark