Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors alh1mik

Also known as: tracked as, it Mischief Night, reachable AMO, then AMOS, active until March 2024, OSx Stealer, AMOS, the panic, the XSS ban, balaclava

Description

Alh1mik, a previously active underground developer known as 0xFFF, re-emerged in 2024 with the notnullOSX macOS stealer. Built in Go and released in March 2026, the malware is purpose‑built to target macOS users who hold more than $10,000 in cryptocurrency wallets such as Exodus, Atomic, Trust and MetaMask. The tool gathers a wide array of data—iMessage history, Apple Notes, Safari cookies, browser credentials, SSH keys, cloud provider creds, Telegram messages, IP addresses—and even overwrites legitimate wallet binaries with fake clones to mislead users. NotnullOSX employs a modular architecture that enables dynamic remote updates via persistent WebSocket connections to Firebase infrastructure. It initially infects a Mac by tricking the user into downloading a malicious DMG file (often named after popular apps like WallSpace) from ClickFix or through a spear‑phishing link in Google Ads. Social engineering prompts the victim to grant Full Disk Access, thereby bypassing macOS TCC protection without triggering any permission dialogs. Once executed the stealer runs as a background agent for persistence, exfiltrates data over encrypted C2 channels, and provides the operator with an admin panel where stolen credentials can be viewed or sold. The operator sells access to the threat‑as‑a‑service model at $400 per month. Alh1mik’s operations illustrate a blend of technical sophistication—modular Go code, WebSocket C2—and high‑reward social engineering tactics. Overall, the actor is focused on lucrative cryptocurrency targets and leverages cloud infrastructure for command and control while maintaining stealth through TCC bypass and legitimate‑appearing DMG files.

Goals & Targeting

Targeted Sectors

Financial services
Media

Targeted Countries / Regions

Spain
Taiwan
TW
ES
RU

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 6 hours ago

Executive Summary

Alh1mik (formerly 0xFFF) operates a subscription‑based macOS stealer called notnullOSX that targets users with high‑value cryptocurrency holdings. The malware collects extensive data—messaging history, browser credentials, crypto wallet files, SSH keys and cloud creds—by social‑engineering victims into granting Full Disk Access and then exfiltrates it via WebSocket to Firebase servers. Delivery is carried out through malicious DMG files masquerading as legitimate apps and spear‑phishing via Google Ads and fake protected documents.

Goals & Targeting

Alh1mik’s strategic objective is monetary gain via targeted theft of high‑value cryptocurrency accounts. The attack surface is deliberately limited to macOS users with substantial crypto holdings, ensuring each infection yields a profitable payout. By employing subscription monetization (≈$400/month) the actor converts individual compromises into ongoing revenue streams while using stealthy C2 mechanisms and social engineering to broaden its campaign reach. The targeting profile focuses on financial‑services and media sectors within Spain, Taiwan, Russia and other European markets where crypto adoption is notable. The actor also appears willing to target any macOS user that can supply credentials to popular wallets and cloud services. Because the malware captures both wallet files and browser data, it can be used for credential stuffing or direct wallet theft, making it attractive for broader financial crime networks.

Enhanced Description

Key Capabilities

  • Steal iMessage history
  • Apple Notes
  • browser credentials
  • Safari cookies
  • crypto wallet files
  • SSH keys
  • cloud provider credentials
  • IP addresses
  • Telegram data
  • replace legitimate hard‑wallet apps with fake ones
  • obtain Full Disk Access via social engineering
  • modular architecture with remote updates via WebSocket to Firebase
  • persistent C2 channel using WebSockets
  • subscription-based service model
  • spear‑phishing via Google Ads and malicious DMG files

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 13 IPv4 Address 3 Domain 4

References

  1. www.infostealers.com — Cited by web research for: reachable AMO
  2. moonlock.com — Cited by web research for: the panic
  3. rectifyq.com — Cited by web research for: T1204.002
  4. www.intego.com — Cited by web research for: Malicious files
  5. moonlock.com — Cited by web research for: MacSync

Intel Summary

20

Techniques

43

Tools

0

Campaigns

41

IOCs

0

Observed Data

10

Tactics

Tags

Financial Targeting
Backdoor / C2
macOS-targeted malware
financial espionage
cryptocurrency theft
social engineering campaigns
sophisticated persistence
Fileless Malware

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
55%
Added
May 18, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.