Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Miolab Stealer

161
Global rank
141 infographic chevron month
Month rank
194 infographic chevron week
Week rank
0
IOCs

Miolab Stealer is a macOS malware threat designed to steal user credentials and sensitive files without raising immediate suspicion. It relies on fake system prompts and legitimate built-in tools to make malicious actions look routine. Instead of causing obvious disruption, it quietly collects valuable data and prepares it for exfiltration from the device. By blending deception with trusted macOS behavior, it increases the chance that the attack will go unnoticed in its early stages. This makes early behavioral detection critical before the theft of credentials and files is complete.

Stealer
Type
Unknown
Origin
1 November, 2025
First seen
14 August, 2026
Last seen
Also known as
Nova

How to analyze Miolab Stealer with ANY.RUN

Type
Unknown
Origin
1 November, 2025
First seen
14 August, 2026
Last seen

IOCs

IP addresses
17.137.162.2
17.248.209.69
17.242.218.132
17.57.144.10
188.114.97.3
17.57.146.29
17.57.144.11
17.253.15.149
151.101.3.6
17.57.146.57
17.253.145.10
17.57.146.23
17.57.147.4
17.57.144.55
146.75.123.6
17.57.144.12
17.57.146.59
2.23.244.214
17.57.147.5
17.57.146.56
Hashes
f9d31b278e215eb0d0e9cd709edfa037e828f36214ab7906f612160fead4b2b4
d286c7aa59052c28a12e65c92aaf67b371b4006c9606c1bb9e1e2ec12db31813
b6e957393e38bebb6d6eb5c47c8ae737e96ddd17cc6ae74b8fee22e60857a6dc
eeadd51e0199ba59d6c338238d097bddd5703810cac4140cd2ea7a8dd852ef98
bac8866ae3234fb69134faec6f35fb57f26c22ad08f0389a9e34e93110fde25f
5623c08e0b1d1776de3e4fbcbd058f64c012cc8eec4662505c58752c7278a044
4dda695b6fb377871e32642810a54f9cd4299da42832cf6288fac9a546cfdb68
26c159e2793d4c5c4909eec73b3bbfa63ff27d115016c81222948e19ecca551c
04f8996da763b7a969b1028ee3007569eaf3a635486ddab211d512c85b9df8fb
0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
83f0d1a4a60ad0a24a705ce1d7485a1712c0f15d6525f1e33cd7ae7a6707ca37
dc2c2c3a0e54d21d1d9f50d9cd48021fad095feb03f0060c0d2fe8ec5dbbda0d
04d509b67c15fda7a4bbea34b67ef2ccc53f0104e383d7d555bc5c83b82e5f06
4e2c0396e96e3e5d763fdcba313ace876ca45333c7683a087698768ff2ea277f
7ed27171bae239c7c93642de4c1783c75c5b81630f5e60a3cbf16b3229415ba4
5ef8d90c8caa717de0f9d3c617836ef4a609163ee13e2288b5411ff919a323ce
324abad8a51ad82bf0f2ba8686caef8f6b4e32d197a9f6377463040e31e6d4bc
28085ec4541851bde26db7e87ef965672d9b70191d88bc86a7f23faa9b9066dc
65b8dbd6a36f51a2b02ff4736f0bd10bb3bbdd7faf5370fb566292996c384db1
b941ad76b99c50a53c6fcf9155d6a2528ee67ebc354aa5a24a5555367b44b331
Domains
50.courier-push-apple.com.akadns.net
2.courier-push-apple.com.akadns.net
6.courier-push-apple.com.akadns.net
25-courier.push.apple.com
setup.icloud.com
38.courier-push-apple.com.akadns.net
32-courier.push.apple.com
9.courier-push-apple.com.akadns.net
41.courier-push-apple.com.akadns.net
47-courier.push.apple.com
20.courier-push-apple.com.akadns.net
gdmf-ados.apple.com
49.courier-push-apple.com.akadns.net
42.courier-push-apple.com.akadns.net
43.courier-push-apple.com.akadns.net
gspe1-ssl.ls.apple.com
29.courier-push-apple.com.akadns.net
24.courier-push-apple.com.akadns.net
fpinit.itunes.apple.com
1-courier.sandbox.push.apple.com
URLs
https://bag.itunes.apple.com/bag.xml?deviceclass=macintosh&format=json&os=os%20x&osversion=15.3.1&product=com.apple.itunescloudd&productversion=1.0&profile=itunescloudd&profileversion=1&storefront=143443-2,42
https://apps.mzstatic.com/content/768f4c5bdaa643daadae50102ef6473f/journeysv2.jetpack
https://apps.mzstatic.com/content/on-device-journeys-exporter/content/ums-locales.json
https://apps.mzstatic.com/content/ma_j9fdyzuhteg1c23uyue3eg/en-gb.json
https://apps.mzstatic.com/content/ma_2r2jcetaqw6c2l4u6yyc0g/en-gb.json
https://apps.mzstatic.com/content/ma_xldxfpx7t4gmzuezorecrw/en-gb.json
https://apps.mzstatic.com/content/ma_6p3zxowmpce1bt6mkbmuxz/en-gb.json
https://apps.mzstatic.com/content/ma_nttnzu1vv2vtgbxnwl5ual/en-gb.json
https://apps.mzstatic.com/content/ma_1i4jnsl_swaqikvbq5qaqa/en-gb.json
https://apps.mzstatic.com/content/ma_wmarubpyfk1y6ziu9uwcwi/en-gb.json
https://apps.mzstatic.com/content/ma_e9hqwdhgrt2y1pqtmnbdfz/en-gb.json
https://apps.mzstatic.com/content/ma_fbutcfzuxh9v8gxvoenfrg/en-gb.json
https://experiments.apple.com/web/treatment_provider/config.json
https://fpinit.itunes.apple.com/v1/signsapsetup
https://is2-ssl.mzstatic.com/image/thumb/pmbs35wdrbkxomj-6hva7a/4320x3240.heic
https://is5-ssl.mzstatic.com/image/thumb/sya7ohe_qwjqaesiv1mryq/4320x3240.heic
https://sf-api-token-service.itunes.apple.com/apitoken?clientclass=apple&clientid=com.apple.amp.journeys&os=os%20x&osversion=15.3.1&productversion=1.0&version=2
https://images-mercury.mzstatic.com/image/thumb/xe3hr434xgmhhex993aahg/4320x3240.heic
https://images-mercury.mzstatic.com/image/thumb/9d34fh85blizncxx4a800g/4320x3240.heic
https://images-mercury.mzstatic.com/image/thumb/iti_voaphrpfj2nvddjxoq/4320x3240.heic
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2800
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 7890
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10855
comments 0

Miolab Stealer: The macOS Threat That Uses Fake System Prompts to Steal Credentials and Sensitive Files

Key Takeaways

  • Miolab Stealer is built for deceptive credential theft on macOS: Rather than relying on exploit-heavy or noisy execution, it uses a fake system authentication prompt to trick the user into entering their password and gain the access it needs to continue.

  • The attack depends on social engineering as much as malware behavior: A legitimate-looking macOS dialog is central to the infection flow, helping the threat reduce suspicion and making the activity appear like a normal system request instead of a credential theft attempt.

  • Trusted native macOS tools help it stay less noticeable: Miolab Stealer uses built-in utilities such as dscl, system_profiler, osascript, ditto, and curl, allowing malicious actions to blend into normal operating system behavior and making static detection less reliable.

  • Credential theft is only part of the objective: After validating the user’s password, the malware gathers system information and collects files from directories such as Desktop, Documents, and Downloads, showing that the attack is aimed at broader data theft, not just access capture.

  • Data collection is selective and structured for exfiltration: The malware uses AppleScript to identify and copy files of interest, stores them in a hidden temporary folder, compresses them into an archive, and prepares them for outbound transfer to its command-and-control infrastructure.

  • Behavioral analysis is critical for catching Miolab Stealer early: Because the threat relies on deception, native tools, and a quiet collection-and-exfiltration chain, the clearest way to understand it is to observe the full behavior in a sandbox before stolen credentials and files leave the device.

Observe Miolab Stealer detonated in the sandbox

Miolab malware analysis in Interactive Sandbox Miolab fresh sample analysis in Interactive Sandbox

What is Miolab Stealer malware?

Miolab Stealer (also known as Nova) is a macOS data theft threat built to capture credentials and pull sensitive information from infected devices without drawing much attention. Instead of using loud or destructive behavior, it relies on deception and built-in macOS tools to make malicious activity look like part of a normal system process. That makes it especially dangerous in business environments where a fake authentication request or routine-looking script execution may not immediately stand out.

What gives Miolab Stealer its strength is the way it combines user manipulation with native operating system behavior. It does not simply run and steal data in a visible way. First, it pressures the user into entering their system password through a convincing prompt. After that, it uses legitimate utilities already present on macOS to validate access, collect host details, locate useful files, package the stolen data, and send it out of the environment. This approach helps the malware stay quiet while still carrying out meaningful theft.

For security teams, Miolab Stealer represents more than a simple infostealer. It shows how macOS threats are increasingly designed to blend into trusted workflows and abuse legitimate system functionality rather than depend only on traditional malware tactics. In practical terms, that means defenders may not see obvious signs of compromise until credentials have already been captured and documents have already been staged for exfiltration.

The real risk is not just the malware itself, but what stolen credentials and internal files can lead to next. Access to a user password combined with collected business documents can give attackers valuable insight into the environment, expose sensitive internal information, and create opportunities for broader compromise. That is why Miolab Stealer should be viewed as a serious operational threat, not just a narrow case of file theft on Apple devices.

How Miolab Stealer Threatens Businesses and Organizations

Miolab Stealer creates business risk by targeting two things organizations cannot afford to lose quietly: user credentials and internal files. Because the malware hides behind a believable macOS authentication prompt and uses native system tools, the attack can look routine at first glance. That makes early detection harder and gives attackers more time to collect sensitive information before the security team understands what is happening.

Main risks include:

  • Unauthorized access through stolen credentials: If an employee enters a valid macOS password into the fake prompt, attackers gain a direct path to privileged user access on the device. That can increase exposure beyond the initial endpoint.

  • Silent theft of sensitive business data: Miolab collects files from common user locations such as Desktop, Documents, and Downloads, where corporate documents, contracts, internal notes, and client materials are often stored.

  • Harder detection in the early stages: The malware uses legitimate macOS utilities and normal-looking system behavior, which can reduce obvious signs of compromise and delay triage.

  • Longer investigation and response time: When malicious activity blends into trusted operating system processes, SOC teams may need more time to confirm what happened, what was accessed, and what data may have been taken.

  • Greater organizational exposure without obvious disruption: Unlike threats that immediately encrypt files or break systems, Miolab can still create serious damage through quiet credential theft and data exfiltration alone.

Victimology: Which Industries Are Most at Risk?

Miolab Stealer is most dangerous in environments where macOS devices are widely used, employees regularly handle sensitive business documents, and stolen credentials could lead to broader access across company systems. Because the malware focuses on password theft and quiet file collection rather than visible disruption, the highest risk is not limited to one narrow sector. It is strongest in organizations where a single compromised user device can expose valuable data.

The risk is especially relevant for:

  • Technology and software companies: These environments often rely heavily on macOS devices, and employee machines may contain product documents, internal communications, credentials, and development-related files.

  • Creative, marketing, and design teams: Mac devices are common across creative functions, where local systems may store brand assets, campaign plans, client deliverables, contracts, and other sensitive materials valuable to attackers.

  • Professional services firms: Legal, consulting, financial, and advisory organizations often keep confidential client documents and business records on employee endpoints, making quiet file theft especially risky.

  • Startups and fast-growing companies: In smaller or rapidly scaling environments, security controls may not fully match the pace of device adoption, giving threats more room to operate unnoticed.

  • Executives and high-value employees using macOS: Leadership, finance, operations, and other decision-making roles can be especially exposed because their devices often contain strategic documents, sensitive communications, and access to important business systems.

More broadly, Miolab Stealer poses the greatest risk to organizations with three conditions: widespread Mac usage, valuable files stored on user devices, and limited visibility into early-stage behavior on endpoints. In those environments, a threat like this can lead to meaningful business exposure even without causing obvious disruption.

How Can Businesses Proactively Protect Against Miolab Stealer Malware?

Businesses can reduce the risk of Miolab Stealer by focusing on the points where the malware is most effective: credential theft through deception, abuse of native macOS tools, and quiet file exfiltration. Because this type of threat can look like normal user or system activity, prevention depends on combining user protection, behavioral visibility, and stronger monitoring of suspicious endpoint actions.

Behavior-based detection on macOS: Use interactive sandbox to monitor for suspicious use of native utilities such as osascript, dscl, system_profiler, ditto, and curl, especially when they appear in unusual sequences tied to password prompts, file staging, or outbound transfer activity.

Credential prompt awareness and user training: Train employees to be cautious with unexpected authentication dialogs, even when they look like legitimate system messages. A convincing fake prompt can be enough to start the attack chain.

Limit sensitive file exposure on endpoints: Reduce the amount of sensitive data stored locally on user devices where possible, especially in directories commonly targeted for collection such as Desktop, Documents, and Downloads.

macOS endpoint monitoring and hardening: Ensure endpoint controls can detect suspicious AppleScript execution, unusual archive creation, hidden temporary staging folders, and command-line data uploads. These actions may be more revealing than the malware file itself.

Access control and credential hygiene: Use least-privilege access, strong credential policies, and additional controls around sensitive systems so that one stolen password does not automatically create wider business exposure.

How Miolab Gets in the System and Functions

Miolab Stealer does not rely on noisy execution or obvious system disruption. Its attack flow is built around user deception, credential capture, file collection, and quiet exfiltration. Instead of forcing access through a visible exploit chain, it appears to depend on convincing the victim to interact with what looks like a legitimate macOS system request. That makes the infection more difficult to recognize in its early stages and gives the malware a cleaner path to sensitive data.

Its operation can be broken into several key phases:

Phase 1: Deceptive User Prompt

The attack begins with a fake macOS system dialog that asks the user to enter their password. The window is designed to closely resemble a legitimate system authentication message, making it more likely that the victim will trust it and respond.

Phase 2: Credential Validation

After the password is entered, the malware checks whether it is valid using the dscl -authonly command. This allows the threat to confirm that it has captured working credentials before moving forward with the rest of the operation.

Phase 3: System Profiling

Once authentication succeeds, Miolab gathers information about the infected device. It uses the system_profiler utility to collect system and hardware details, helping attackers better understand the host they have compromised.

Phase 4: File Discovery and Collection

The malware then launches an AppleScript-based routine to search user directories such as Desktop, Documents, and Downloads. It selectively copies files with extensions like PDF, TXT, and RTF into a hidden temporary folder, suggesting a focus on documents that may contain useful business or personal information.

Phase 5: Staging and Compression

After collecting the files, Miolab prepares them for removal from the system. It uses the ditto utility to compress the gathered data into a ZIP archive, making the stolen content easier to transfer in a single package.

Phase 6: Data Exfiltration and Cover-Up

In the final stage, the archive is sent to a command-and-control server through an HTTP POST request executed with curl. After the upload, the malware displays another fake error message to make the activity appear like a failed system action and reduce the chance that the user will suspect credential theft or file exfiltration.

Miolab’s execution chain shows how a macOS threat can move from a simple fake prompt to confirmed password theft and document exfiltration without creating obvious disruption. That is what makes early behavioral visibility so important.

Sandbox Analysis of Miolab Malware Sample

See full execution chain of Miolab Stealer

ANY.RUN sandbox revealing Miolab Stealer behavior in real time ANY.RUN sandbox revealing Miolab Stealer behavior in real time

The analyzed Miolab sample begins by displaying a fake macOS system authentication prompt designed to look like a legitimate password request. Its goal is to convince the user to enter their system password without suspecting malicious activity. This deceptive step is central to the attack, because the malware does not continue unless valid credentials are provided.

Legitimate-looking authentication prompt revealed inside ANY.RUN sandbox Legitimate-looking authentication prompt revealed inside ANY.RUN sandbox

Once the password is entered, the malware validates it using the dscl -authonly command. This allows the sample to confirm that the stolen credentials are valid before moving deeper into the attack chain. After successful validation, Miolab starts gathering information about the compromised device with the system_profiler utility, collecting system and hardware details that can help attackers better understand the host.

System profiling activity observed inside ANY.RUN macOS sandbox System profiling activity observed inside ANY.RUN macOS sandbox

The malware then proceeds to file collection. Using an AppleScript-based routine launched through osascript, it scans user directories such as Desktop, Documents, and Downloads for files that may contain useful information. In the analyzed case, the malware selectively copies files with extensions such as PDF, TXT, and RTF into a hidden temporary directory. The collected files are renamed sequentially, and the total size of the staged data is kept within an approximate 10 MB limit.

AppleScript-driven file collection detected inside the sandbox AppleScript-driven file collection detected inside the sandbox

After staging the collected files, Miolab prepares them for exfiltration. It uses the ditto utility to compress the stolen content into a ZIP archive, creating a single package that can be transferred more efficiently. The archive is then sent out through an HTTP POST request using curl, showing a clear exfiltration step rather than simple local collection.

ANY.RUN sandbox detects outbound data upload via curl POST ANY.RUN sandbox detects outbound data upload via curl POST

To reduce suspicion, the malware finishes by displaying another fake error message, making the whole sequence appear to the user like a failed or harmless system action. This final step helps hide the true purpose of the attack and lowers the chance that credential theft and file exfiltration will be noticed immediately.

Fake error message used to disguise malicious activity Fake error message used to disguise malicious activity

Conclusion

Miolab Stealer shows how a quiet macOS threat can still create serious business risk. By combining a fake authentication prompt, native macOS tools, selective file collection, and outbound exfiltration, it can steal credentials and sensitive data without causing obvious disruption.

The concern is simple: a threat does not need to encrypt systems or break workflows to become a serious incident. If it can capture passwords, collect internal files, and move data outside the environment while appearing legitimate, the result can still include data loss, unauthorized access, longer investigations, and broader operational exposure.

This is why sandbox analysis needs to be carried out during earlier triage. Seeing the full execution chain in one place helps security teams quickly understand what the malware is doing, assess the impact more confidently, and respond before the damage grows.

Use ANY.RUN’s Interactive Sandbox to observe Miolab Stealer’s full behavior, understand its real impact, and give your team clearer evidence for faster response: Sign up to ANY.RUN.

HAVE A LOOK AT

DarkComet screenshot
DarkComet
darkcomet rat darkcomet rat
DarkComet RAT is a malicious program designed to remotely control or administer a victim's computer, steal private data and spy on the victim.
Read More
Fog Ransomware screenshot
Fog is a ransomware strain that locks and steals sensitive information both on Windows and Linux endpoints. The medial ransom demand is $220,000. The medial payment is $100,000. First spotted in the spring of 2024, it was used to attack educational organizations in the USA, later expanding on other sectors and countries. Main distribution method — compromised VPN credentials.
Read More
Spyware screenshot
Spyware
spyware
Spyware is a stealth form of malware whose primary objective is to gather sensitive information, such as personal data, login credentials, and financial details, by monitoring user activities and exploiting system vulnerabilities. Spyware operates secretly in the background, evading detection while transmitting collected data to cybercriminals, who can then use it for malicious purposes like identity theft, financial fraud, or espionage.
Read More
MetaStealer screenshot
MetaStealer
metastealer
MetaStealer is an info-stealing malware primarily targeting sensitive data like login credentials, payment details, and browser history. It typically infects systems via phishing emails or malicious downloads and can exfiltrate data to a command and control (C2) server. MetaStealer is known for its stealthy techniques, including evasion and persistence mechanisms, which make it difficult to detect. This malware has been actively used in various cyberattacks, particularly for financial theft and credential harvesting from individuals and organizations.
Read More
GuLoader screenshot
GuLoader
guloader
GuLoader is an advanced downloader written in shellcode. It’s used by criminals to distribute other malware, notably trojans, on a large scale. It’s infamous for using anti-detection and anti-analysis capabilities.
Read More
Cephalus screenshot
Cephalus
cephalus
Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.
Read More