216.73.216.6

NovaStealer - Apple Intelligence is leaving a plist.. it is legit, right?

· Published 14/11/2025 12:04 · Modified 14/11/2025 12:44

Export JSON

Essential information

Published
14/11/2025 12:04
Modified
14/11/2025 12:44
Tags
2025-11-14 bash cryptostealer macos modular novastealer persistence phishing wallet-targeting
Related entities
7 observables, 1 malware

Description

A for utilizes a -based script to establish and execute malicious modules. The malware installs itself in the ~/.mdrivers directory, uses screen sessions for background execution, and employs a LaunchAgent for . It exfiltrates crypto wallet data, collects system information, and replaces legitimate wallet applications with malicious versions. The threat actor employs clever techniques like using WebKit to render pages and tracking user behavior. While not highly sophisticated, the nature and ability to update components remotely make it a noteworthy threat.

External references