Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators “Say My Name”: How MioLab is building MacOS Stealer Empire

owqkoqoqoqoqoqqoqoo.info

TLP:CLEAR
Active

Domain

Description

MioLab, also known as Nova, is a sophisticated Malware-as-a-Service platform targeting macOS environments, heavily advertised on Russian-speaking underground forums. The platform features extensive data exfiltration capabilities, including browser credential theft, cryptocurrency wallet targeting (supporting over 200 browser extensions and 50+ desktop wallets), and a premium module specifically designed to compromise Ledger and Trezor hardware wallets by intercepting 24-word BIP39 recovery seed phrases. The lightweight C-based payload supports both Intel and Apple Silicon architectures across macOS versions from Sierra to Tahoe. MioLab employs sophisticated social engineering through customizable DMG builders with live preview features, fake system prompts, and ClickFix integration. Recent updates demonstrate rapid development, including Safari cookie grabbing, automated Apple Notes decryption, and universal hardware wallet modules. The operation utilizes bulletproof hosting services a...

Sightings (0)

No sightings recorded yet

Details

Name / Label
“Say My Name”: How MioLab is building MacOS Stealer Empire
Pattern Type
STIX
Confidence
75%
Valid From
May 6, 2026 04:50
Total Sightings
0
Added
May 6, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of owqkoqoqoqoqoqqoqoo.info

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.