Approaching stealers devs: a brief interview with notnullOSX
To completely understand what’s going on in a market that has been growing in the last years I found mandatory to know which players are dominating it. Always remember that behind every user of the Internet there is another human like you, so if you can be kind enough to reach them and they agree, you can have a little talk. Asking things is not a crime.
Please note everything that stated on this blog has only an informational purpose. I will never promote the use of these products.
This interview was made in collaboration with friend and amazing MacOS researcher xiu (@osint_barbie). Thank you for all the dedication and passion about the MacOS infosec landscape you share with me.
Please find some context about this malware here: https://moonlock.com/notorious-hacker-returns-notnullosx-stealer
Let’s see today, a brief talk with notnullOsX:
The interview was made both in English and Russian. Original text is provided below.
What is notnullOSx?
NotnullOSx is less a product and more a concept. It shows that even systems considered safe are only as strong as the assumptions behind them.
notnullOSx — это скорее не продукт, а концепция. Он показывает, что даже системы, которые считают безопасными, защищены ровно настолько, насколько верны лежащие в их основе предположения.
Is there a history behind this name notnullOSx?
Yes, there is actually a lot of meaning and history behind this name, but I would rather leave it for the community. Maybe they will figure it out themselves. One person already solved this “riddle”.
Да, причем в этом нике смысла и истории очень много, но я бы хотел оставить это для комьюнити, возможно они сами поймут смысл этого ника. Один человек уже разгадал эту “загадку”))
How many people do you think have used notnullOSx? Approximately
Fewer than you think. More than you would be comfortable with. At the moment, around 25 active clients with a monthly subscription.
Меньше, чем вы думаете. И больше, чем вам хотелось бы. На данный момент около 25 активных клиентов которые приобрели месячную подписку
Since when has the stealer been operating?
Since March 3, 2026.
3 марта 2026 года
What makes notnullOSx different from competitors? What do you offer your clients to convince them to choose your product?
We are creators, not opportunists. We are not chasing quick money. We are building an ecosystem — a seamless architecture that already proves itself through easy module integration, instant panel deployment, and fast hotfix updates.
We are also the only ones with a working Safari password module under the hood. We are still deciding how to deliver it to clients, because including something like that in a $4k subscription would be unreasonable.
Мы команда созидателей, нам не нужны деньги здесь и сейчас. Мы строим экосистему, бесшовную архитектуру которая уже принесла свои плоды в виде легкости добавления новых модулей, молниеносной установке панелей, таким же быстрым обновлением панелей с hot фиксами критических проблем. У нас у единственных есть под капотом модуль, который крадет Safari пароли, пока у нас идут дискусии в каком виде его подавать клиентам, ибо включать такой модуль в подписку за 4k$ — глупость.
Why did you decide to release a stealer in Go language?
I just like it. But we might move to another language soon to reduce build size.
Он мне нравится, но возможно в скором времени мы перейдем на другой язык, чтобы уменьшить вес билда.
Do you leverage AI for developing? How much of the original codebase was AI-assisted?
AI is a perfect tool in the right hands. It helps with ideas and speeds up development when you hit a dead end.
We never trusted it to write actual stealer modules — everything core is written by us. There was one attempt to generate a simple Firefox password decryptor with Claude, but it refused, so we didn’t push it further. We know those limitations can be bypassed, but honestly we just coded it ourselves in about 30 minutes.
Some parts of the web panel, maybe 15 to 20 percent, were AI-assisted.
AI — это идеальный инструмент в хороших руках. Он ускоряет разработку креативов, помогает развить мысли когда ты зашел в тупик. Писать код для модулей стиллера мы ему еще никогда не доверяли, все пишем сами. Насколько я знаю, была какая то попытка написать простенький декрипт Firefox паролей с помощью Claude, но он отказал в выполнении, и мы не стали дальше его мучать, хотя на 100% знаем, что эти ограничения легко обойти, в итоге сами за полчаса это накодили. Но некоторые элементы веб панели (15–20%) — писал AI
Are you working alone, or do you have coders involved this time?
No one really works alone. Some contributors are just less visible.
Никто по-настоящему не работает один. Просто некоторые участники менее заметны.
What advantages do you see in the modular architecture, downloading and staging individual binaries per function rather than shipping everything in one binary?
Flexibility always outlives monoliths.
Гибкость всегда переживает монолиты.
We saw the Firebase endpoint mactest-6b2ab-default-rtdb[.]firebaseio.com used in the code. Why did you choose Firebase?
Sometimes the most obvious places are the least suspicious. Firebase is just one of several communication methods we rotate for better stealth.
Иногда самые очевидные места оказываются самыми незаметными. Firebase это лишь один из некоторых способов клиент-серверного соединения, наш продукт чередует еще несколько способов, для более незаметной работы
In the code we observed the path /Users/angola/Documents/mactest/modules/telegram_grab.go. What is Angola, is it nickname of your ’teammate-’coder, a project codename or something else?
It’s nothing special. Just the admin account name on one of our macOS VPS servers that was located in Africa. First thing that came to mind was “angola”.
Ха-ха, это просто название admin аккаунта одной из наших macOS VPS, которая находилась в Африке, и первое что пришло в голову при выборе названия аккаунта, это почему то — angola 😆
Is notnullOSx designed to function as a RAT beyond data collection, or is the channel currently used only for exfiltration and callbacks?
Definitions depend on perspective. We already have a solid reverse shell, but we want to expand functionality before fully calling it a RAT.
Определения зависят от точки зрения. У нас уже есть хороший reverse-shell, но мы хотим добавить больше функциональности чтобы иметь 100% право называть продукт — RAT
Do you plan to add iCloud credential exfiltration modules?
This is one of the main directions we are currently focusing on.
Это одно из главных направлений куда мы сейчас развиваемся
Can you share what improvements we are going to see in notnullOSx in the future?
Smaller footprint. Smarter behavior. Less visibility. And Safari passwords, of course.
Меньше следов. Умнее поведение. Меньше заметности. И Safari пароли конечно
Does notnullOSx works on the CIS countries?
Absolutely not.
Ни в коем случае
How do you see the MacOS market? Is this a good time to work?
It is underestimated, and that makes it interesting. Competition is almost nonexistent, mostly script kiddies.
If you compare feedback, it becomes obvious. I once had a short conversation with a competitor and realized immediately how easy this space is. The guy didn’t even understand what he was talking about and was running his panel behind Cloudflare, basically sending his clients’ data straight to law enforcement.
Он недооценен. Именно это делает его интересным. Конкуренция на нуле. Только скрипт кидди. Если сравнить мои отзывы на форуме, с отзывами других участников рынка — все становится понятно. У меня был один диалог с моим “конкурентом”, он отправил несколько сообщений, и я понял, что игра слишком легкая 😆, человек вообще не понимает о чем говорит, и держит панель на Cloudflare (LOL), чтобы данные его клиентов летели прямо в руки ФБР и Интерполу
Where do you see macOS threat development heading next, I mean, beyond classic info-stealing. Are backdoors/botnets the next wave, or do you see another one, different vectors for attacks on Macs?
Botnets on macOS are not very practical. I think everything is moving toward more sophisticated ways of stealing cryptocurrency.
От macOS ботнета смысла мало, я думаю все идет к более изощренным способам воровства криптовалюты.
What would you say to those “information security experts” who are trying to track notnullOSx?
If you are looking for something obvious, you are already too late.
You can write a million articles, try to trace C2 infrastructure, it doesn’t really cause any damage. I actually have good relationships with some researchers. There is mutual respect, and sometimes I even help them understand parts of the system.
It’s a cat and mouse game. If they find something today, it will be gone in the next build.
Если вы ищете что-то очевидное, вы уже опоздали. Вы можете писать миллион статей о том, как работает notnullOSx, пытаться палить IP наших c2 серверов, просто это не наносит никакого урона. Я со многими ресерчерами в хороших отношениях, у нас есть взаимное уважение, и я даже иногда помогаю в ресерче моего продукта. Это ведь кошки-мышки, ресерчер найдет за что можно зацепиться — в следующем билде уже этой зацепки не будет. И так каждый день.
End
Dear reader,
Remember to check the other interviews at: g0njxa — Medium
Expect more content, if possible.
My best wishes to you ❤
