PANews reported on April 24 that 23pds, Chief Information Security Officer of SlowMist, stated in an article on the X platform that MioLab is a highly commercialized macOS Malware-as-a-Service (MaaS) platform actively promoted on Russian-language underground forums, specifically targeting cybercrime groups by providing C2 control, API integration, and customized attack capabilities. Its primary objective is the theft of encrypted assets, and it even provides dedicated attack modules targeting hardware wallets such as Ledger and Trezor.
With a lightweight payload and a fully functional web backend, attackers can efficiently steal sensitive browser data and encrypted wallet assets, and bypass macOS security protections with highly customized social engineering decoys to achieve more covert long-term control.

