Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Malware Targets MacOS to Steal Cryptocurrency

New Malware Targets MacOS to Steal Cryptocurrency

Posted on April 23, 2026 By CWS

In early 2026, a new threat emerged for Mac users as a sophisticated malware named notnullOSX began targeting digital asset holders. Designed to steal cryptocurrency from anyone holding digital assets worth over $10,000, this malware poses a significant risk by masquerading as legitimate software throughout its infection process.

Background and Development of notnullOSX

The origins of this malware trace back to 2023, involving a developer known as 0xFFF who vanished from a notorious hacking forum over fears of investigation by security services. Returning in 2024 under the alias alh1mik, he offered a new macOS stealer, which later materialized as notnullOSX. This malicious software was crafted using the Go programming language and distributed through social engineering, a counterfeit wallpaper app, and a compromised YouTube channel.

Distribution and Targeting Tactics

Moonlock Lab detected notnullOSX on March 30, 2026, across Vietnam, Taiwan, and Spain. The malware’s distribution involves sophisticated layers, including fake Google documents and a hijacked YouTube channel. Operators identify targets by submitting forms detailing users’ wallet addresses and balances, ensuring victims have assets exceeding $10,000 before proceeding.

The initial attack vector is a deceptive Google document, leading victims to believe they need to fix an encryption error caused by an outdated API. Options provided either download the malware through a Terminal command or a disk image masquerading as a wallpaper app. The compromised YouTube account used to lure victims had amassed significant views, indicating a hijacking incident.

Functionality and Risks of notnullOSX

Once installed, notnullOSX operates covertly, extracting information from various applications and browser sessions. It can replace legitimate wallet apps with malicious versions to capture seed phrases, maintaining a connection with the attacker’s server for ongoing instructions. This makes it a persistent threat to macOS users.

The infection chain relies on user trust in Terminal commands. A base64 command decodes into a script fetching a binary from a server, bypassing Apple’s security measures by requiring Full Disk Access. This grants the malware comprehensive access to sensitive data without user prompts.

Preventative Measures Against notnullOSX

To mitigate this threat, users should avoid executing Terminal commands from untrusted sources and be wary of applications requesting Full Disk Access. Regular audits of system folders and monitoring for unusual network activities can also help detect unauthorized activities. Security teams should block suspicious connections and flag unusual file downloads for further investigation.

Staying informed and vigilant is crucial as cyber threats evolve. Follow trusted sources for updates on cybersecurity measures and potential threats.

Cyber Security News Tags:cryptocurrency theft, cyber threat, Cybersecurity, digital assets, fake applications, hacking tactics, Mac security, macOS malware, malware prevention, notnullOSX, online safety, tech security, Terminal commands

Post navigation

Previous Post: Chinese Cybersecurity Firm’s AI Claims Rival Top Models
Next Post: Rituals Cosmetics Reveals Member Data Breach Incident

Related Posts

New Sophisticated Attack Bypasses Content Security Policy Using HTML-Injection Technique New Sophisticated Attack Bypasses Content Security Policy Using HTML-Injection Technique Cyber Security News
175 Malicious npm Packages With 26,000 Downloads Attacking Technology, and Energy Companies Worldwide 175 Malicious npm Packages With 26,000 Downloads Attacking Technology, and Energy Companies Worldwide Cyber Security News
MacOS Screen Sharing Issue in Microsoft Teams MacOS Screen Sharing Issue in Microsoft Teams Cyber Security News
INE Named to Training Industry’s 2025 Top 20 Online Learning Library List INE Named to Training Industry’s 2025 Top 20 Online Learning Library List Cyber Security News
Threat Actors Could Misuse Code Assistant To Inject Backdoors and Generating Harmful Content Threat Actors Could Misuse Code Assistant To Inject Backdoors and Generating Harmful Content Cyber Security News
Malicious Skills Found in OpenClaw’s ClawHub Marketplace Malicious Skills Found in OpenClaw’s ClawHub Marketplace Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Kali365 Exploits Microsoft Codes to Breach Accounts
  • Hackers Exploit MFA to Hijack Microsoft 365 Sessions
  • Windows NT Kernel Vulnerability PoC Publicly Released
  • AWS Kiro Vulnerability Enables Remote Code Execution
  • ASUS Fixes Critical Router Flaw Allowing Remote Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Kali365 Exploits Microsoft Codes to Breach Accounts
  • Hackers Exploit MFA to Hijack Microsoft 365 Sessions
  • Windows NT Kernel Vulnerability PoC Publicly Released
  • AWS Kiro Vulnerability Enables Remote Code Execution
  • ASUS Fixes Critical Router Flaw Allowing Remote Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark