Malware research lab @moonlock_com Assembled by @macpaw to detect and study cybersecurity threats.

Our team recently published 2026 #macOS malware predictions: supply-chain + AI/workflow (MCP) abuse, signed/notarized stealth & multi-stage loaders, Macs as proxy infrastructure, and “upmarket” infostealers. Give it a read! 👇 moonlock.com/macos-malware-t…
1
9
29
4,476
1/🧵 New suspicious #macOS implant, and it's currently FUD on VirusTotal, shared by @malwrhunterteam. We're calling it OpsLoader (from its own codesign identifier). It fingerprints your Mac, phones home and blindly executes whatever its operator sends back. Breakdown below 👇
3
9
39
7,638
7/ OpsLoader is (obviously) just a loader, not a full stealer - no persistence, no keychain/clipboard/screen access observed. Its whole job is: recon + beacon + run whatever it's told. The payload lives wherever the operator points it next. Will staging build become prod soon?..
1
1
5
174
8/ IOCs 🧙 3220acfe8afe73c9beec11714cb95e324c56fe3386c5109fcd4cb5ba4873c3a5
1
6
546
New #Mac #stealer in the wild: Sonoma. Crazy Evil's 2026 kit. Same crew we wrote about in 2024. Impersonated brands we saw so far: StreamYard, Zoom, Slack, DocSend, Brave Talk, Toria, Waaako, Meendo, CavePay, Crystal Flip, Cốc Cốc. Some fun facts: - one chain fetched the next stage from Apple Calendar. - the first loaders still used /tmp/osalogging.zip. That's a MacSync leftover. They borrowed pieces. - it talks to PAM, so it looked like Avenger (PamStealer), but it isn't Read more: hackernoon.com/downloading-z…
12
37
2,917
⚡️We currently observe an ongoing campaign mentioned by @ossmalware - utilizing NullReceiver and adding more IP addresses to its list. Last transaction happened hours ago. This time, the same sender initiates transfers to a new address which decodes to 166.88.73[.]46. Ref: opensourcemalware.com/blog/n…
2
8
32
2,059
Source (same): 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a Destination (new): 0xa658492Ea658492e68656C6C6f6970626f742121 Decoding: a6 58 49 2e -> 166 88 73 46
2
5
502
1/ Spent the morning on a batch of #macOS #infostealers and one of their components caught our eye: a keylogging thread literally named "goida.keyhammer". Universal (fat) Mach-O, x86_64 + arm64, ad-hoc signed, no Team ID. All uploaded to VT on Aug 4. Some of them are 0/70 detects. Analysis is ongoing, we share early findings while we keep digging. 🧵
2
10
36
3,260
7/ The wire protocol constants are sitting in sobf3cfg: - APP_WIRE_IPC_IM_START / IM_STOP / IM_STATUS (start, stop and poll the input-monitoring module on demand) - APP_WIRE_MODULE_INPUT_MON - APP_WIRE_TASK_PRIV_SYNC So the keylogger is operator-toggled, not always-on. That has real implications for sandbox work: run the agent alone and you may see almost nothing, because nothing ever told it to start. The lldb run also spews "com\.apple\.linkd.autoShortcut" XPC failures, it tries to register with the Intents framework and can't, being ad-hoc signed.
1
1
2
273
8/ IOCs 🧙 Undetected on VT (at time of writing): 44b761515af601f2ab974dea4ea9cc14c40b5b2d5eec5cda2cf16ac6110b4bed 6030d755457f2236c4c63bb21e843098a6db93db00e44df03e8e414b1d28ff9c b07e6d197fd296bda1700a8ccdbdd5da8f59159032a139a8dcb203106717d50e Detected on VT: 4ca6427d9949482e7fed2a073b8c35b25ce4e4a710b3e34f618ca42027840466 459305bdc6d1e9a1a70da46460f2990ad59ef335c04caca2d4218cca062b4105 800559c2d7f51d59ce9cae595c217f056413602e1727ffaba6aca216e1b99768 If you've got runtime telemetry on any of these, we'd love to compare notes 🌙
1
3
251
Moonlock Lab retweeted
Few weeks after, I'm still thinking how incredible #OFTW in Berlin was🔥 Loved chatting with so many of you after my presentation :3 The panel with @patrickwardle, @gergely_kalman and @naehrdine was an absolute privilege, listening to their thoughts and experience was something else! Deep appreciation to @objective_see, @patrickwardle & @andyrozen for everything they do, and to @HPI_DE for hosting such a great even and amazing people. And of course, shoutout to the @moonlock_lab team for the support 🩷
5
19
5,280