● 0 online
ANALYZING THREAT INTELLIGENCE
CTI
PORTAL
Threat Intelligence
INTELLIGENCE
Dashboard
IOC Search
Bulk Search
Pulses
Actors
Tags
Watchlist
ANALYSIS
Phishing
Knowledge Base
SYSTEM
Cache
← Back to Pulse Feed
PULSE
DETAIL
PULSE NAME
A new Mac stealer targeting $10K+ crypto wallets
WHITE
alh1mik
Tr1sa111
2026-04-16
Modified: 2026-04-16
15
IOCs
MEDIUM VOLUME
↓ CSV
↓ JSON
★ Watch
cryptocurrency theft
poseidon stealer
macos stealer
atomic macos stealer
notnullosx
clickfix
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
T1056.001
T1539
T1036.005
T1204.002
T1566.002
T1119
T1005
T1140
T1555.003
T1552.004
T1087
T1083
T1552.001
T1041
T1059.004
T1562.001
T1573.002
T1543.001
T1071.001
T1564.001
MALWARE FAMILIES
notnullOSX
Atomic macOS Stealer
Poseidon Stealer
Banshee
Cthulhu
Indicators of Compromise (15)
All
FileHash-SHA256
IPv4
URL
domain
⎘ Copy All
TYPE
INDICATOR
DESCRIPTION
CREATED
FileHash-SHA256
070402c2c531aa3a87b9ccd080532a51d17b01d982b205fc4487246d58de8913
—
2026-04-16
⎘
FileHash-SHA256
4584d02b5193799453766857dba97021f966b9cbf6033d7dd3a33d61eb975a6c
—
2026-04-16
⎘
FileHash-SHA256
47373950e1d23c066de0ed2d511b4b7eea56ec22d7b501db265995fec51dbb44
—
2026-04-16
⎘
FileHash-SHA256
636fa90aebab98534dcdbe50508ed8d3607c284c72f831a4503e223540d3f761
—
2026-04-16
⎘
FileHash-SHA256
82cb3a22c90aee6cfc2f7e7f72e921e21226492c1d424d2b754b9cd763ab0b20
—
2026-04-16
⎘
FileHash-SHA256
8d029b65c1076141d4817f25428cef44888b2fb4349ab9b9df7a413d240e1177
—
2026-04-16
⎘
FileHash-SHA256
b0cd860f18b0136e063d7ef9a3c84d138a1a21dbea019605ce66a3a1fad91db4
—
2026-04-16
⎘
FileHash-SHA256
b73adc5dc04159241e4a89cbc82eaa381f406080f3aaaa1f27d145900dd54267
—
2026-04-16
⎘
FileHash-SHA256
ff7f0c39aa90ed8f4ce24658a347e7871bb5f6a607eaedf2cf2859a1fb5782a9
—
2026-04-16
⎘
IPv4
111.90.149.111
—
2026-04-16
⎘
IPv4
83.217.209.88
—
2026-04-16
⎘
URL
http://wallpapermacos.com/download/
—
2026-04-16
⎘
domain
coockie.pro
—
2026-04-16
⎘
domain
wallpapermacos.com
—
2026-04-16
⎘
domain
wallspaceapp.com
—
2026-04-16
⎘
References (1)
↗ https://moonlock.com/notorious-hacker-returns-notnullosx-stealer