Gate News message, April 24 — Slow Mist Chief Information Security Officer 23pds disclosed on X that MioLab is a highly commercialized macOS malware-as-a-service (MaaS) platform actively promoted on Russian underground forums, offering C2 control, API integration, and customized attack capabilities to cybercriminal groups.
The platform specifically targets cryptocurrency asset theft and provides dedicated attack modules against hardware wallets including Ledger and Trezor. Attackers can efficiently steal sensitive browser data and crypto wallet assets using lightweight payloads combined with a fully functional web backend. The platform leverages highly customized social engineering lures to bypass macOS security protections, enabling stealthier long-term control.
The discovery highlights the evolving sophistication of MaaS platforms targeting the cryptocurrency ecosystem, particularly those exploiting macOS systems that may have lower security awareness among some users.
Related News
Bitwarden CLI malicious npm package exposed, encrypted wallets face risk of theft
Slow Mist Alert: North Korean hacker group recruits and tricks Web3 developers, stealing 12 million in 3 months
SlowMist CISO issues alert: ShinyHunters claims to have breached Anthropic’s internal systems