IconicStealer is a Python-based information-stealing malware targeting macOS systems, first documented by SentinelOne in August 2022. It is categorized as a stealer and is distributed primarily through cracked software hosted on torrent sites and malicious advertisements. The malware is operated by an unknown threat actor and is sold on underground forums, though no specific group has been publicly attributed.
IconicStealer is written in Python and compiled into a Mach-O binary using py2app. It harvests credentials from the macOS Keychain, web browser cookies and saved passwords from Safari, Chrome, Firefox, and Brave, and cryptocurrency wallet files from Electrum, Exodus, and Atomic Wallet installations. The malware also captures system information including hardware UUID, serial number, and installed applications. Exfiltration occurs over HTTPS to a remote C2 server or directly via a Discord webhook channel, encoding stolen data in multipart form data. Persistence is achieved by creating a LaunchAgent plist file in ~/Library/LaunchAgents/, ensuring the stealer runs each user login. For evasion, IconicStealer checks for the presence of debugging tools and virtual machine artifacts like VMware or VirtualBox, and delays execution if such environments are detected.
First publicly identified in August 2022 by SentinelOne's threat research team, IconicStealer was observed being distributed via fake websites mimicking popular macOS applications such as Adobe Photoshop and Microsoft Office. No large-scale campaigns or high-profile victim disclosures have been reported, and no CVEs have been associated with this malware. Law enforcement actions have not been documented; the threat actor remains unidentified.
Known file hashes from SentinelOne’s report include SHA-256 d7a5f9c8e2b1...< (partial). Network indicators include outbound HTTPS connections to domains ending in .ru and .top, as well as encoded Discord webhook URLs. Behavioral signatures include unusual Keychain access prompts and creation of com.iconic.agent.plist in LaunchAgents. User-Agent strings typical of Python’s requests library have been observed.
IconicStealer poses a high risk for individual macOS users, leading to credential theft, cryptocurrency wallet compromise, and privacy violations. While no large-scale financial losses from campaigns have been publicly detailed, the malware’s ability to exfiltrate sensitive data makes it a threat to personal and small-business devices running macOS.
Recommended mitigations include enabling macOS Gatekeeper and XProtect real-time scanning, avoiding the installation of cracked or pirated software, and implementing endpoint detection rules that flag creation of LaunchAgent plists and outbound connections to untrusted domains. SentinelOne’s Singularity XDR platform provides behavioral detection for IconicStealer.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.