0xFFF
0xFFF, also known as alh1mik, is the threat actor attributed in the provided reporting to the development of the macOS malware notnullOSX. The actor was described as having published notnullOSX earlier in the year after returning to a major hacking forum previously left three years earlier. In the reported activity, notnullOSX was used in a ClickFix campaign observed on March 30 targeting macOS users with cryptocurrency wallets holding more than $10,000, including victims in Taiwan, Vietnam, and Spain. The campaign used social engineering lures including a fake protected Google Document referencing an outdated Google API Connector and a malicious WallSpace app promoted through a hacked YouTube channel. Victims were instructed to copy and execute a command in macOS Terminal, which downloaded notnullOSX and sought total disk access. Reported malware functionality included multiple modules, notably ReplaceApp, which replaced legitimate Trezor and Ledger Live applications with counterfeit versions to steal seed phrases in real time. No nation-state attribution is stated in the provided content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Financial Services
Where they target
Geographies tied to known operations.
- 🇹🇼 Taiwan
- 🇻🇳 Vietnam
- 🇪🇸 Spain
Tradecraft
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Observables
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.