The Mac Malware of 2025
2026-01-01 • Objective-see •
Objective-See’s 2025 macOS malware review shows information stealers as the dominant new macOS malware class, with victims’ cookies, passwords, certificates, cryptocurrency wallets, SSH keys, and related sensitive data as primary collection targets. The excerpt highlights MaaS-style distribution, where stealer authors sell malware while traffer teams spread it through fake updates, malvertising, and ClickFix-style terminal command scams. Kitty Stealer is presented as an arm64 Mach-O sample focused on Chrome data and Exodus cryptocurrency wallet files, with strings showing collection paths for Chrome cookies, Chrome passwords, and Exodus wallet artifacts. Its behavior includes retrieving the system serial number through system_profiler, prompting for Chrome Safe Storage access via Security Framework APIs, and making outbound requests that include victim-derived identifiers. The excerpt does not attribute Kitty or the broader 2025 macOS malware set to a DPRK actor, but it is relevant to crypto-security monitoring because stealer infections can precede asset theft and broader compromise.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 67e5143a9ca7d2240c137ef80f2641d6 | 2026-01-01 | 2026-01-01 |
| HASH | 1e5234329ce17cfcee094aa77cb6c801 | 2026-01-01 | 2026-01-01 |
| HASH | 9e410d7320e53cfa145597824b9f6060 | 2026-01-01 | 2026-01-01 |
| HASH | 2bbfdf3250a663cf7c4e10fc50dfc7da | 2026-01-01 | 2026-01-01 |
| HASH | 6f0cdc9eaead1ca53c40d1c82b4180e… | 2026-01-01 | 2026-01-01 |
| HASH | f42bb3a975870049d950dfa861d0edd4 | 2026-01-01 | 2026-01-01 |
| HASH | c9c114433040497328fe9212012b1b94 | 2026-01-01 | 2026-01-01 |
| HASH | 054e6893413402d220f5d7db8ef24af0 | 2026-01-01 | 2026-01-01 |
| URL | https://brsp.meshsorterio.com | 2026-01-01 | 2026-01-01 |
| URL | https://support.us05web-zoom.bi… | 2026-01-01 | 2026-01-01 |
| URL | https://steamcommunity.com/id/p… | 2026-01-01 | 2026-01-01 |
| URL | https://brsp.meshsorterio.com/a… | 2026-01-01 | 2026-01-01 |
| URL | https://dynamiclake.org | 2026-01-01 | 2026-01-01 |
| URL | https://function.undefined21.co… | 2026-01-01 | 2026-01-01 |
| URL | https://67e5143a9ca7d2240c137ef… | 2026-01-01 | 2026-01-01 |
| URL | https://goldenticketsshop.com/a… | 2026-01-01 | 2026-01-01 |
| URL | https://67e5143a9ca7d2240c137ef… | 2026-01-01 | 2026-01-01 |
| URL | https://support.us05web-zoom.biz | 2026-01-01 | 2026-01-01 |
| URL | https://goldenticketsshop.com | 2026-01-01 | 2026-01-01 |
| URL | https://67e5143a9ca7d2240c137ef… | 2026-01-01 | 2026-01-01 |
| URL | https://67e5143a9ca7d2240c137ef… | 2026-01-01 | 2026-01-01 |
| URL | https://67e5143a9ca7d2240c137ef… | 2026-01-01 | 2026-01-01 |
| URL | https://function.undefined21.co… | 2026-01-01 | 2026-01-01 |
| URL | https://meshsorterio.com/api/da… | 2026-01-01 | 2026-01-01 |
| URL | https://goldenticketsshop.com/a… | 2026-01-01 | 2026-01-01 |
| URL | https://goldenticketsshop.com/a… | 2026-01-01 | 2026-01-01 |
| URL | https://67e5143a9ca7d2240c137ef… | 2026-01-01 | 2026-01-01 |
| DOMAIN | meshsorterio.com | 2026-01-01 | 2026-01-01 |
| DOMAIN | dynamiclake.org | 2026-01-01 | 2026-01-01 |
| DOMAIN | function.undefined21.com | 2026-01-01 | 2026-01-01 |
| DOMAIN | sweetseedsbeep.com | 2026-01-01 | 2026-01-01 |
| DOMAIN | lasso-security.com | 2026-01-01 | 2026-01-01 |
| DOMAIN | goldenticketsshop.com | 2026-01-01 | 2026-01-01 |
| DOMAIN | brsp.meshsorterio.com | 2026-01-01 | 2026-01-01 |
| DOMAIN | askforupdate.org | 2026-01-01 | 2026-01-01 |
| DOMAIN | 67e5143a9ca7d2240c137ef80f2641d… | 2026-01-01 | 2026-01-01 |
| IPv4 | 82.115.223.9 | 2026-01-01 | 2026-01-01 |
| URL | http://web071zoom.us/fix/audio-… | 2025-10-28 | 2026-01-01 |
| URL | http://web071zoom.us/fix/audio-… | 2025-10-28 | 2026-01-01 |
| DOMAIN | safeupload.online | 2025-10-28 | 2026-01-01 |
| DOMAIN | web071zoom.us | 2025-10-28 | 2026-01-01 |
| DOMAIN | support.us05web-zoom.biz | 2025-06-18 | 2026-01-01 |
| IPv4 | 5.255.101.148 | 2025-02-26 | 2026-01-01 |