New macOS (crossplatform) sample
2026-06-25 • Moonlock •
Moonlock Lab identified a macOS cross-platform RAT masquerading as MicrosoftSystem64, with a JavaScript payload bundled inside a Mach-O binary through `__NODE_SEA_BLOB`. The malware provides full surveillance and remote-control capabilities, including adaptive screenshot streaming, keylogging with password-field detection, clipboard monitoring, file operations, shell execution, self-update, and uninstall commands. It targets browser credentials, secrets files, and more than 50 cryptocurrency wallets, then uses a WebSocket endpoint for tasking and small exfiltration while abusing an operator-controlled Hugging Face dataset for bulk exfiltration.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://huggingface.co/jpeek998… | 2026-06-25 | 2026-06-25 |
| HASH | f981d0470ff0c7afafe2d08e91a55c1… | 2026-06-25 | 2026-06-25 |
| IPv4 | 195.201.194.107 | 2026-04-15 | 2026-06-25 |