Search TorWire

Find cybersecurity guides and research articles

Home > News > Deep Web > Dark Web Seller Advertises ICMacOS Stealer Targeting Keychain, Crypto Wallets and Telegram

Dark Web Seller Advertises ICMacOS Stealer Targeting Keychain, Crypto Wallets and Telegram

By: Morgan Cipher — Senior Privacy Journalist

Last updated: September 19, 2026

Human Written
Dark Web Seller Advertises ICMacOS Stealer Targeting Keychain, Crypto Wallets and Telegram
  • A forum actor named GlowComa claims ICMacOS Stealer works on macOS Sierra 10.12 and newer systems.

  • The ad says this malware can steal your Keychain, browser history, crypto wallets, Telegram sessions, and cloud logins.

  • While there’s proof that malware stealing information on macOS is a real problem, there’s no public information that confirms this specific ICMacOS malware family actually exists.

A threat actor using the handle ‘GlowComa’ is peddling a macOS stealer called ICMacOS Stealer on a Russian forum. The pitch claims it supports macOS Sierra 10.12 and newer, and works on both x86_64 Intel and ARM64 Apple silicon machines.

The malware appears to operate on a subscription basis: one week for 699, two weeks at 1,199, then one month for 1,699. But it’s unclear what currency these amounts are, since it wasn’t indicated in the post.

The advert also promotes a control panel with infection statistics and stolen-log counts. It claims buyers get Telegram alerts when new data arrives. Further, the listing also claims ongoing updates, encrypted tokens, and configurable VPS infrastructure.

Those are typical features of a malware-as-a-service model where developers sell access to malware while giving customers access to a panel to manage stolen data. Still, the listing is only a claim. I found no public technical report, malware sample, or independent vendor analysis that confirms ICMacOS Stealer under that exact name.

What the Seller Says It Can Steal

The advert claims a broad collection range, including macOS Keychain data that often contains passwords and other confidential info. There are also browser cookies, history, and auto-fill data on the list of info the malware steals. Plus, it claims to target Chrome, Edge, Brave, Opera, Firefox, and Safari.

The seller also claims support for cryptocurrency wallet extensions. That could make the tool attractive to criminals seeking access to crypto accounts and assets. Other claimed targets include Telegram session data, AWS and Kubernetes credentials, SSH information, terminal history, and environment variables.

The listing also says the malware can grab files from the Desktop and Documents folders. It mentions Notes, payment card data, and information linked to two-factor authentication. If accurate, that mix would expose several high-value parts of a Mac user’s digital life. But these are advertised capabilities, not tested results.

Session data remains a valuable target for malware because stolen tokens can sometimes give attackers access to accounts without requiring a password. Researchers recently warned that malicious wallpapers on Steam were used to steal gaming session data, showing how attackers can hide credential-stealing activity behind seemingly harmless content.

The claims match a wider macOS threat trend

The broader threat picture makes the listing plausible, even though the specific claim remains unverified.

Palo Alto Networks Unit 42 recently examined Atomic macOS Stealer, or AMOS, in a lab using indicators from August 2O26. The researchers described AMOS as an active macOS stealer that can collect login credentials, browser data, system information, and crypto wallet data.

Microsoft also reported, in February 2O26, that macOS infostealer campaigns were expanding. Its researchers observed threats such as DigitStealer, MacSync and AMOS. Some campaigns used fake installers and ClickFix-style tricks to persuade users to run malicious commands.

Malwarebytes also reported in March that SHub Stealer targeted Keychain data, browsers, crypto wallets, Telegram sessions, Apple Notes and shell history. That means the features claimed by ICMacOS are not unusual on their own. There’s a similar macOS malware already out in the wild targeting the same data sources.

Apple’s Built-in Defenses aren’t Guaranteed Malware Protection

MacOS has a number of features that identify and prevent malware attacks. The elements include Gatekeeper, notarization, and XProtect.

Gatekeeper scans downloaded applications and prevents untrusted applications from executing. XProtect can detect known malware and receive automatic security updates. In addition, Apple mentions that Macs with Apple silicon have additional security measures that can limit the risk of malware damage.

However, there are still several other ways through which attackers strike. These include social engineering and malicious advertising that trick people into running unsafe apps. Recent research from Microsoft and Unit 42 shows that these methods remain active against Mac users.

No Confirmed Victims or Infections Yet

The biggest gap in the ICMacOS story is evidence of real-world activity. The forum advert shows what the seller claims to offer. It does not show confirmed victims, infection numbers or technical findings from a trusted security lab.

A separate web domain that currently displays an ‘ICMacOs Panel Login’ page, escapeai.live, has also drawn security warnings. Gridinsoft reported on Sept. 11 that the domain was created in March 2026 and had nine external security-provider warnings.

That finding shows the domain has a suspicious reputation, but it does not prove that the advertised ICMacOS malware caused any infections. An automated threat feed currently links escapeai.live to AMOS. That is useful as a lead, but it does not establish that ICMacOS Stealer and AMOS are the same malware.

For now, ICMacOS Stealer should be treated as an unverified criminal-market offering. The touted features resemble those you’d find in known macOS infostealers. But there’s still need for independent research to confirm whether the tool exists as the seller described and how widely attackers are using it.

Share this article

You might also like

Hacker Claims Vodafone Core Database Breach, Posts Encrypted Sample

Hacker Claims Vodafone ‘Core Database’ Breach, Posts Encrypted Sample on Dark Web

A dark web threat actor claims to have breached a Vodafone core database, posting an encrypted sample file rather than…

September 15, 2026
LAPSUS$ Name Reappears Online as ‘Chapter II’ Claims Group Has Returned

LAPSUS$ ‘Chapter II’ Reappears Online, but Original Group’s Return Remains Unverified

A new site using the LAPSUS$ name claims the group has returned under ‘Chapter II.’ The message mentions TeamPCP, which…

September 10, 2026
Cybercriminal Claims 195 Million Identity Records are for Sale for $90,000

Dark Web Seller Claims 195 Million U.S. and Canadian ID Records for Sale at $90,000

A cybercriminal listed a 195 million-record identity dataset on a dark web forum for $90,000, targeting US and Canadian individuals.…

September 7, 2026

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.