Moonlock Lab

468 posts

Moonlock Lab banner
Moonlock Lab

Moonlock Lab

@moonlock_lab

Malware research lab @moonlock_com Assembled by @macpaw to detect and study cybersecurity threats.

Katılım Haziran 2023
70 Takip Edilen1.5K Takipçiler
Sabitlenmiş Tweet
Moonlock Lab
Moonlock Lab@moonlock_lab·
Our team recently published 2026 #macOS malware predictions: supply-chain + AI/workflow (MCP) abuse, signed/notarized stealth & multi-stage loaders, Macs as proxy infrastructure, and “upmarket” infostealers. Give it a read! 👇 moonlock.com/macos-malware-…
English
1
8
28
2.9K
Moonlock Lab
Moonlock Lab@moonlock_lab·
IOCs 🧙 b3ff86f6fc849693a84e525b4839a58111c530c60fb117739a23dc7a7441f56c 292a74d8e56e7605802cace34f2ee9adef38a1455970b7468a83061ad86550da b93494549d589123455cd244d75765df29fdaf12b29f3faa4a16483d702a435f ada7fd7409b64c2e0ee8aa0cea747a756561440b9ddb465ebad600d3ae1b1c1f task-vault-54a2-356814497283.us-central1[.]run[.]app 2df91afaee60aa8a5dca05ff48acc26ea9096b7d6efb4cfc8911461ff9c63dad (Win EXE)
Italiano
1
1
6
386
Moonlock Lab
Moonlock Lab@moonlock_lab·
1/ New #macOS samples, 0 detections on VT as of writing, but multiple artifacts suggest Sliver-like HTTP(S) C2. Shared by @malwrhunterteam. What stood out: procedural URL patterns, PNG-wrapped network payloads, no plaintext IOCs, and wazero/WASM-related execution. More below👇
Moonlock Lab tweet media
English
3
12
42
5.6K
Moonlock Lab
Moonlock Lab@moonlock_lab·
We’re seeing a significant number of #SHub #stealer samples in the wild, with detections spanning multiple countries. Especially concerning is that it also impersonates CleanMyMac, abusing a trusted brand to target users (x.com/cleanmymac/sta…). This is another reminder that macOS stealers remain a growing threat. Our team is tracking it, and our customers are protected by Moonlock. See the map for the current detection footprint. 👇
Moonlock Lab tweet media
CleanMyMac by MacPaw@cleanmymac

⚠️ Important security notice: A fraudulent website is currently impersonating CleanMyMac and distributing macOS malware. It presents a fake installation prompt and instructs users to open Terminal and paste a command. CleanMyMac will never ask you to do this. Ever. Only download CleanMyMac from official sources: ✅ macpaw.com/cleanmymac ✅ Mac App Store ✅ Setapp Marketplace If you've encountered this site or believe you may have been affected, please change your passwords and run a trusted malware scanner immediately. Stay safe online!

English
0
8
26
3K
Moonlock Lab retweetledi
Moonlock by MacPaw
Moonlock by MacPaw@moonlock_com·
We’re excited to share something special with the community. Moonlock Lab experts @osint_barbie and @xor3r have published a new piece on the RSA Conference blog about the evolving landscape of macOS threats. In the article they break down the most common threats targeting macOS today, how these attacks have evolved, and what security teams should be paying attention to next. Proud to share this knowledge with the community 🙌🏻 #RSAC rsaconference.com/library/blog/m…
English
0
4
25
1.2K
Moonlock Lab
Moonlock Lab@moonlock_lab·
Beware fake VCs on LinkedIn ❗️ Our latest Moonlock Lab report tracks a new #ClickFix campaign using fake Zoom/Meet links + a bogus Cloudflare CAPTCHA to trick victims into pasting malicious commands - cross-platform for macOS & Windows. Featuring findings by @malwrhunterteam and analysis by @L0Psec 🔎 Give it a read 👉 moonlock.com/fake-vcs-targe…
English
0
9
23
6.7K
Moonlock Lab
Moonlock Lab@moonlock_lab·
Infostealers aren’t slowing down. Listen to the second part of @9to5mac Security Bite Podcast with @arinwaichulis, where our Moonlock Lab researchers break down how these threats land, and why social engineering is escalating. 🎙️ 9to5mac.com/2026/02/24/sec…
English
0
3
11
1.1K
Moonlock Lab
Moonlock Lab@moonlock_lab·
🧙IOC: f33c7e03d14de2053daf69f745e209744599acbad8d5bd725afbdcbbae773e03
CY
1
3
6
694
Moonlock Lab
Moonlock Lab@moonlock_lab·
1/ We just triaged a #macOS sample that looks like a full-featured RAT with a twist - it uses the #Solana blockchain as part of its C2 workflow. Kindly shared by @malwrhunterteam. More below 🧵
Moonlock Lab tweet media
English
1
12
63
7.8K