New macOS (crossplatform) sample

2026-06-25 Moonlock

https://archive.md/NAcCm

Thumbnail for New macOS (crossplatform) sample

Moonlock Lab identified a macOS cross-platform RAT masquerading as MicrosoftSystem64, with a JavaScript payload bundled inside a Mach-O binary through `__NODE_SEA_BLOB`. The malware provides full surveillance and remote-control capabilities, including adaptive screenshot streaming, keylogging with password-field detection, clipboard monitoring, file operations, shell execution, self-update, and uninstall commands. It targets browser credentials, secrets files, and more than 50 cryptocurrency wallets, then uses a WebSocket endpoint for tasking and small exfiltration while abusing an operator-controlled Hugging Face dataset for bulk exfiltration.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://huggingface.co/jpeek998… 2026-06-25 2026-06-25
HASH f981d0470ff0c7afafe2d08e91a55c1… 2026-06-25 2026-06-25
IPv4 195.201.194.107 2026-04-15 2026-06-25

Related Reports

« Back