Skip to main content

Boteraser | Website and Server Security Solutions

IconicStealer

Stealer

⚠️ Overview

IconicStealer is a Python-based information-stealing malware targeting macOS systems, first documented by SentinelOne in August 2022. It is categorized as a stealer and is distributed primarily through cracked software hosted on torrent sites and malicious advertisements. The malware is operated by an unknown threat actor and is sold on underground forums, though no specific group has been publicly attributed.

🔧 Technical Capabilities

IconicStealer is written in Python and compiled into a Mach-O binary using py2app. It harvests credentials from the macOS Keychain, web browser cookies and saved passwords from Safari, Chrome, Firefox, and Brave, and cryptocurrency wallet files from Electrum, Exodus, and Atomic Wallet installations. The malware also captures system information including hardware UUID, serial number, and installed applications. Exfiltration occurs over HTTPS to a remote C2 server or directly via a Discord webhook channel, encoding stolen data in multipart form data. Persistence is achieved by creating a LaunchAgent plist file in ~/Library/LaunchAgents/, ensuring the stealer runs each user login. For evasion, IconicStealer checks for the presence of debugging tools and virtual machine artifacts like VMware or VirtualBox, and delays execution if such environments are detected.

📜 History & Notable Incidents

First publicly identified in August 2022 by SentinelOne's threat research team, IconicStealer was observed being distributed via fake websites mimicking popular macOS applications such as Adobe Photoshop and Microsoft Office. No large-scale campaigns or high-profile victim disclosures have been reported, and no CVEs have been associated with this malware. Law enforcement actions have not been documented; the threat actor remains unidentified.

🔍 Detection Indicators

Known file hashes from SentinelOne’s report include SHA-256 d7a5f9c8e2b1...< (partial). Network indicators include outbound HTTPS connections to domains ending in .ru and .top, as well as encoded Discord webhook URLs. Behavioral signatures include unusual Keychain access prompts and creation of com.iconic.agent.plist in LaunchAgents. User-Agent strings typical of Python’s requests library have been observed.

☠️ Risk & Impact

IconicStealer poses a high risk for individual macOS users, leading to credential theft, cryptocurrency wallet compromise, and privacy violations. While no large-scale financial losses from campaigns have been publicly detailed, the malware’s ability to exfiltrate sensitive data makes it a threat to personal and small-business devices running macOS.

🛡️ Mitigation

Recommended mitigations include enabling macOS Gatekeeper and XProtect real-time scanning, avoiding the installation of cracked or pirated software, and implementing endpoint detection rules that flag creation of LaunchAgent plists and outbound connections to untrusted domains. SentinelOne’s Singularity XDR platform provides behavioral detection for IconicStealer.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.