MonetaStealer is a newly discovered macOS information-stealing malware (Python-based, packaged with PyInstaller) first identified by Iru researchers on 2026-01-06. It has been distributed via social engineering and deceptive file disguises, including an unsigned Mach-O binary masquerading as a Windows executable named "Portfolio_Review.exe" ("Portfolio_review.exe" also referenced for a Windows-labeled variant). The campaign leverages the misconception that .exe files are harmless on macOS and appears aimed at professionals likely to receive portfolio files.
Behavior and capabilities (as reported):
security find-generic-password -w -a "Chrome" (triggering a Keychain password prompt); then queries passwords, session cookies, and browsing history via SQL. Cookie theft filters for high-value targets by matching hostnames containing keywords such as "bank," "crypto," "exchange," and "paypal."security find-generic-password for Wi‑Fi passwords) and searches keychain dumps for keywords like "crypto," "bank," and "paypal."Packaging/implementation notes:
portfolio_app.pyc embedded in a compressed PyInstaller CArchive.Exfiltration:
b746_mac_collector_bot (bot ID: 8384579537).Associated actors/targeting:
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Python-based stealer malware family; noted as capable of targeting Apple macOS systems for data theft.
Post navigation Previous:Fake Windows Executables Target macOS: Inside the “MonetaStealer” Discovery
macOS-focused infostealer delivered as an unsigned Mach-O binary masquerading as a .exe. Bundled via PyInstaller with malicious logic in a compressed Python bytecode file (portfolio_app.pyc). Targets Chrome data (passwords/cookies/history), cryptocurrency wallets (e.g., MetaMask, Exodus, Electrum, Phantom, Binance) and searches for seed phrases/private keys, and attempts to dump macOS Keychain and Wi‑Fi credentials via the native `security find-generic-password` command; relies on user authorization prompts for keychain access.
MonetaStealer is a macOS-focused information stealer delivered as a PyInstaller-packed Mach-O binary masquerading as a Windows .exe. It targets and exfiltrates sensitive data including Google Chrome credentials/cookies/history (decrypting via Keychain master key retrieval), cryptocurrency wallet data, Wi‑Fi credentials, SSH keys, and financial documents, and exfiltrates via a Telegram bot infrastructure ("b746_mac_collector_bot").
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.