Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Moonlock

Moonlock Vendor Cyber Rating & Cyber Score

moonlock.com

We are Moonlock – the cybersecurity wing of MacPaw, aspiring to make cybersecurity accessible to everyone. Using MacPaw’s 15-year experience in macOS development, Moonlock is bringing together a dedicated team of researchers and engineers to pack complex security technology into tools anyone could use. The very first Moonlock tech is now powering the Malware Removal module in the award-winning CleanMyMac X. We call it Moonlock Engine. Our in-house research team, Moonlock Lab, locates and analyzes existing and emerging malware to improve threat detection and stay ahead of the curve.


Moonlock A.I CyberSecurity Scoring

Moonlock
Company Information
Website:https://moonlock.com/
Employees number:2
Number of followers:496
NAICS:541514
Industry Type:Computer and Network Security
Homepage:moonlock.com
Moonlock Risk Score (AI oriented)
Between 700 and 749
logo
MoonlockComputer and Network Security
Updated:
10/03/2026
731/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Moonlock Global Score (TPRM)
xxxx
logo
MoonlockComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Moonlock
MoonlockModerate
Current Score
731Ba (MODERATE)
01000
1 incidents
-18 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
733Before Incident
MAY 2026
733Before Incident
APRIL 2026
732Before Incident
MARCH 2026
731Before Incident
FEBRUARY 2026
731Before Incident
JANUARY 2026
748Before Incident
Cyber Attack
25 Jan 2026Moonlock
macOS users: Beware of New Compliance Emails Weaponizing Word/PDF Files to Steal Sensitive Data

Sophisticated macOS Phishing Campaign Targets Users with Fake Compliance Emails

730After Incident
CRITICAL-18
MOO1770130358
Sophisticated macOS Phishing Campaign Targets Users with Fake Compliance Emails A new phishing campaign is targeting macOS users with a multi-stage malware attack disguised as compliance and audit notifications. Discovered by Chainbase Lab, the operation leverages social engineering to trick victims into executing malicious AppleScript files, leading to credential theft and persistent remote access. The attack begins with seemingly innocuous emails requesting basic company details, such as legal names, to establish trust. Victims who respond receive follow-up messages with subject lines like "FY2025 External Audit" or "Token Vesting Confirmation", containing attachments masquerading as Word or PDF files. In reality, these are AppleScript files with double extensions (e.g., Confirmation_Token_Vesting.docx.scpt), designed to evade detection. Researchers at SlowMist identified the malware’s infection chain, which starts with the AppleScript displaying fake macOS system prompts including software update progress bars to distract users while executing malicious code. The script collects system details (CPU architecture, macOS version) and downloads additional payloads from the domain sevrrhst[.]com. To bypass security, the malware presents counterfeit permission dialogs featuring Google avatar elements, tricking users into entering administrator passwords. Once obtained, credentials are Base64-encoded and exfiltrated to the attacker’s server. The malware further evades macOS Transparency, Consent, and Control (TCC) protections by injecting SQL commands into the privacy database, granting itself camera access, screen recording, and keylogging capabilities. Persistence is maintained via a Node.js runtime environment, allowing attackers to execute arbitrary commands. The campaign’s infrastructure relies on throwaway domains registered in January 2026, with the command server at sevrrhst[.]com (IP: 88.119.171.59) hosting multiple malicious domains for reuse.
INCIDENT DETAILS -
TYPE
Phishing, Malware
MOTIVATION
Credential Theft, Remote Access, Data Exfiltration
IMPACT
Data Compromised: Credentials, System Details, Camera Access, Screen Recording, Keylogging DataSystems Affected: macOS SystemsIdentity Theft Risk: High
DATA BREACH
CredentialsSystem DetailsCamera AccessScreen RecordingKeylogging DataSensitivity Of Data: HighData Exfiltration: Base64-encoded credentials exfiltrated to attacker's serverPersonally Identifiable Information: Yes
DECEMBER 2025
748Before Incident
NOVEMBER 2025
748Before Incident
OCTOBER 2025
748Before Incident
SEPTEMBER 2025
748Before Incident
AUGUST 2025
748Before Incident
JULY 2025
748Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Moonlock ?
?
What was Moonlock's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Moonlock's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Moonlock's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Moonlock's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Moonlock's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Moonlock's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Moonlock's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Moonlock's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Moonlock's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Moonlock's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Moonlock's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Moonlock's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Moonlock ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Moonlock's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?