BPOI Banner
MacOS Malware 'Cthulu Stealer' Is Draining Crypto Wallets—Here's How to Spot It MacOS Malware 'Cthulu Stealer' Is Draining Crypto Wallets—Here's How to Spot It

MacOS Malware ‘Cthulu Stealer’ Is Draining Crypto Wallets—Here’s How to Spot It

In a concerning development for macOS users and cryptocurrency holders, security researchers have identified a new malware-as-a-service (MaaS) named “Cthulhu Stealer.”

According to a recent Cado Security report, this malware specifically targets macOS systems, challenging the long-held belief that Apple’s operating system is immune to such threats.

While macOS has maintained a reputation for security, recent years have seen an uptick in malware targeting Apple’s platform. Notable examples include Silver Sparrow, KeRanger, and Atomic Stealer. Cthulhu Stealer is the latest addition to this growing list, indicating a shift in the cybersecurity landscape for macOS users.

Cthulhu Stealer is distributed as an Apple disk image (DMG) file, disguising itself as legitimate software such as CleanMyMac, Grand Theft Auto IV, or Adobe GenP, according to the Cado report. The malware, written in GoLang, is designed for both x86_64 and ARM architectures. This follows recent reports of another crypto-stealing malware targeting Call of Duty players.

Upon execution, the malware uses osascript to prompt users for their system password and MetaMask credentials. It then creates a directory in ‘/Users/Shared/NW’ to store stolen information. The malware’s primary function is to extract credentials and cryptocurrency wallets from various sources, including browser cookies, game accounts, and multiple cryptocurrency wallets.

Cthulhu Stealer shares similarities with Atomic Stealer, another macOS-targeted malware identified in 2023. Both are written in Go and focus on stealing crypto wallets, browser credentials, and keychain data. The resemblance in functionality suggests that Cthulhu Stealer may be a modified version of Atomic Stealer.

The malware is operated by a group known as “Cthulhu Team,” who use Telegram for communication. They offer the stealer for rent at $500 per month as part of a malware-as-a-service model, with affiliates responsible for deployment and receiving a percentage of the earnings.

Malware-as-a-service is a business model in the cybercrime world where malicious software and related services are sold or rented to customers, typically other criminals. This allows individuals or groups without advanced technical skills to conduct cyberattacks using pre-made malware tools and infrastructure. MaaS providers often offer customer support, updates, and customization options, similar to legitimate software services.

However, recent developments suggest trouble within the operation.

Affiliates have lodged complaints against the main developer, known as “Cthulhu” or “Balaclavv,” accusing them of withholding payments, according to Cado’s report. The researchers noted that this has led to the developer being banned from at least one malware marketplace.

Edited by Stacy Elliott.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Source link

Adrian Zmudzinski

https://decrypt.co/246402/macos-malware-cthulu-stealer-is-draining-crypto-wallets-heres-how-to-spot-it

2024-08-26 11:28:48

bitcoin
Bitcoin (BTC) $ 91,334.47 3.84%
ethereum
Ethereum (ETH) $ 3,130.18 2.06%
tether
Tether (USDT) $ 1.00 0.01%
solana
Solana (SOL) $ 220.25 5.26%
bnb
BNB (BNB) $ 625.67 1.05%
xrp
XRP (XRP) $ 0.97212 19.87%
dogecoin
Dogecoin (DOGE) $ 0.380528 2.89%
usd-coin
USDC (USDC) $ 1.00 0.05%
staked-ether
Lido Staked Ether (STETH) $ 3,124.36 1.99%
cardano
Cardano (ADA) $ 0.740063 19.18%
tron
TRON (TRX) $ 0.189453 6.14%
shiba-inu
Shiba Inu (SHIB) $ 0.000025 5.97%
avalanche-2
Avalanche (AVAX) $ 34.89 9.91%
the-open-network
Toncoin (TON) $ 5.41 2.68%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 91,186.43 3.79%
wrapped-steth
Wrapped stETH (WSTETH) $ 3,704.12 2.07%
sui
Sui (SUI) $ 3.77 17.63%
pepe
Pepe (PEPE) $ 0.000022 11.88%
weth
WETH (WETH) $ 3,131.84 2.10%
chainlink
Chainlink (LINK) $ 14.16 7.50%
bitcoin-cash
Bitcoin Cash (BCH) $ 438.69 4.58%
polkadot
Polkadot (DOT) $ 5.30 8.98%
near
NEAR Protocol (NEAR) $ 6.12 12.06%
leo-token
LEO Token (LEO) $ 7.74 3.91%
aptos
Aptos (APT) $ 12.29 5.07%
litecoin
Litecoin (LTC) $ 86.70 5.52%
wrapped-eeth
Wrapped eETH (WEETH) $ 3,293.64 2.04%
uniswap
Uniswap (UNI) $ 8.78 8.40%
usds
USDS (USDS) $ 0.996832 0.85%
stellar
Stellar (XLM) $ 0.154789 16.53%
crypto-com-chain
Cronos (CRO) $ 0.169201 2.91%
internet-computer
Internet Computer (ICP) $ 9.01 12.19%
bittensor
Bittensor (TAO) $ 529.23 5.25%
dogwifcoin
dogwifhat (WIF) $ 3.80 7.65%
kaspa
Kaspa (KAS) $ 0.143806 9.62%
ethereum-classic
Ethereum Classic (ETC) $ 23.80 7.42%
fetch-ai
Artificial Superintelligence Alliance (FET) $ 1.29 4.08%
dai
Dai (DAI) $ 1.00 0.04%
whitebit
WhiteBIT Coin (WBT) $ 22.32 0.77%
ethena-usde
Ethena USDe (USDE) $ 1.00 0.10%
bonk
Bonk (BONK) $ 0.000043 22.88%
polygon-ecosystem-token
POL (ex-MATIC) (POL) $ 0.382017 6.36%
hedera-hashgraph
Hedera (HBAR) $ 0.079973 20.06%
blockstack
Stacks (STX) $ 1.93 7.46%
render-token
Render (RENDER) $ 7.15 8.20%
monero
Monero (XMR) $ 146.64 0.25%
okb
OKB (OKB) $ 44.20 1.81%
first-digital-usd
First Digital USD (FDUSD) $ 1.00 0.26%
filecoin
Filecoin (FIL) $ 4.21 7.59%
aave
Aave (AAVE) $ 167.73 8.17%