216.73.217.22

Analyzing the MonetaStealer macOS Threat

· Published 19/01/2026 09:41 · Modified 19/01/2026 09:58

Export JSON

Essential information

Published
19/01/2026 09:41
Modified
19/01/2026 09:58
Tags
2026-01-19 chrome cryptocurrency keychain macos monetastealer pyinstaller ssh stealer telegram wi-fi
Related entities
1 vulnerabilities (cve), 4 observables, 10 techniques (mitre), 1 malware

Description

Security researchers discovered a suspicious Mach-O binary masquerading as a Windows .exe file, named . This -compiled malware targets systems and is believed to be in early development. focuses on stealing browser data, wallet information, credentials, items, financial documents, private keys, and clipboard content. It uses deceptive naming conventions and targets specific file paths to gather sensitive information. The malware employs various techniques to extract data, including querying SQLite databases, using regex patterns, and executing system commands. Exfiltration is attempted via , although researchers did not observe successful file uploads. A Windows variant was also identified but contained non-functional code. The threat highlights the ongoing prevalence of stealers in the landscape.

External references