PULSE NAME
A new Mac stealer targeting $10K+ crypto wallets
WHITE alh1mik AlienVault 2026-04-15 Modified: 2026-04-15
15
IOCs
MEDIUM VOLUME
A sophisticated macOS stealer called notnullOSX emerged in March 2026, developed by threat actor alh1mik (formerly 0xFFF) who returned after a 2023 exit from underground forums. This Go-written modular stealer exclusively targets macOS users with cryptocurrency holdings exceeding $10,000. Distribution occurs through ClickFix social engineering and malicious DMG files disguised as legitimate applications like WallSpace. The malware employs a modular architecture with specialized components to exfiltrate iMessage history, Apple Notes, browser credentials, Safari cookies, crypto wallet files, SSH keys, and cloud provider credentials. By social-engineering victims into granting Full Disk Access, notnullOSX bypasses macOS TCC protections without triggering permission dialogs. The stealer maintains persistent WebSocket connections to Firebase infrastructure, functioning as both an infostealer and backdoor with remote module update capabilities.
Indicators of Compromise (15)
All FileHash-SHA256 IPv4 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 070402c2c531aa3a87b9ccd080532a51d17b01d982b205fc4487246d58de8913 2026-04-15
FileHash-SHA256 4584d02b5193799453766857dba97021f966b9cbf6033d7dd3a33d61eb975a6c 2026-04-15
FileHash-SHA256 47373950e1d23c066de0ed2d511b4b7eea56ec22d7b501db265995fec51dbb44 2026-04-15
FileHash-SHA256 636fa90aebab98534dcdbe50508ed8d3607c284c72f831a4503e223540d3f761 2026-04-15
FileHash-SHA256 82cb3a22c90aee6cfc2f7e7f72e921e21226492c1d424d2b754b9cd763ab0b20 2026-04-15
FileHash-SHA256 8d029b65c1076141d4817f25428cef44888b2fb4349ab9b9df7a413d240e1177 2026-04-15
FileHash-SHA256 b0cd860f18b0136e063d7ef9a3c84d138a1a21dbea019605ce66a3a1fad91db4 2026-04-15
FileHash-SHA256 b73adc5dc04159241e4a89cbc82eaa381f406080f3aaaa1f27d145900dd54267 2026-04-15
FileHash-SHA256 ff7f0c39aa90ed8f4ce24658a347e7871bb5f6a607eaedf2cf2859a1fb5782a9 2026-04-15
IPv4 111.90.149.111 2026-04-15
IPv4 83.217.209.88 2026-04-15
URL http://wallpapermacos.com/download/ 2026-04-15
domain coockie.pro 2026-04-15
domain wallpapermacos.com 2026-04-15
domain wallspaceapp.com 2026-04-15