BPOI Banner
New Malware Steals Crypto From MetaMask, Binance, and Other Wallets on macOS New Malware Steals Crypto From MetaMask, Binance, and Other Wallets on macOS

This New Malware Can Steal Your Crypto on macOS

Cado Security’s discovery has thoroughly debunked the belief that macOS systems are impervious to malware. This revelation concerns a new malware-as-a-service (MaaS) called “Cthulhu Stealer,” which targets macOS users through deceptive means.

The rise of Cthulhu Stealer indicates that no system is completely secure against cyber threats.

How Malware Steals Mac Users’ Crypto?

Cthulhu Stealer disguises itself as legitimate applications such as CleanMyMac and Adobe GenP and software claiming to be an early release of “Grand Theft Auto VI.

Once the user mounts the malicious DMG file, they are prompted to enter the system and MetaMask passwords. This initial deception is just the beginning.

Read more: A Guide to the Best AI Security Solutions in 2024

Screenshot of Disk Image of Malicious Software. Source: Cado Security

Following the credentials input, the malware utilizes osascript, a macOS tool, to extract passwords from the system’s Keychain. This data, including details from crypto wallets like MetaMask, Coinbase, and Binance, is compiled into a zip archive. This archive, identified by the user’s country code and the time of the attack, contains the stolen information.

Cthulhu Stealer also steals data from other platforms, including:

  • Chrome extension wallets
  • Minecraft user information
  • Wasabi wallet
  • Keychain passwords
  • SafeStorage passwords
  • Battlenet game, cache, and log data
  • Firefox cookies
  • Daedalus wallet
  • Electrum wallet
  • Atomic wallet
  • Harmony wallet
  • Electrum wallet
  • Enjin wallet
  • Hoo wallet
  • Dapper wallet
  • Coinomi wallet
  • Trust wallet
  • Blockchain wallet
  • XDeFi wallet
  • Browser cookies
  • Telegram Tdata account information

Moreover, Cthulhu Stealer collects detailed system information such as IP address, system name, and OS version. It then sends this data to a command and control (C2) server, enabling the attackers to refine their strategies.

Scammers Charge $500/Month For Cthulhu Stealer

Scammers use various strategies to trap the victims into installing the malware. For example, on social media, some scammers pose as employers who offer jobs that require downloading software to track working hours. These offers come with a sense of urgency, pushing the potential victim to download the application quickly.

Screenshots of Scammer Trying to Trap Victim Into Installing Malicious Software
Screenshots of Scammer Trying to Trap Victim Into Installing Malicious Software. Source: Discord Screenshot

The developers and affiliates behind Cthulhu Stealer, known as the Cthulhu Team, use Telegram to manage their operations.

“The stealer appears to be being rented out to individuals for $500/month, with the main developer paying out a percentage of earnings to affiliates based on their deployment. Each affiliate of the stealer is responsible for the deployment of the malware. Cado has found Cthulhu stealer sold on two well-known malware marketplaces which are used for communication, arbitration and advertising of the stealer, along with Telegram,” Cado informed readers.

Read more: 9 Crypto Wallet Security Tips To Safeguard Your Assets

To protect themselves, users should install reputable antivirus software that is specifically designed for macOS. They should also be cautious of employment opportunities that require immediate software downloads. Regular software updates can further reduce the risk of malware infections.

Disclaimer

In adherence to the Trust Project guidelines, BeInCrypto is committed to unbiased, transparent reporting. This news article aims to provide accurate, timely information. However, readers are advised to verify facts independently and consult with a professional before making any decisions based on this content. Please note that our Terms and ConditionsPrivacy Policy, and Disclaimers have been updated.

Source link

Harsh Notariya

https://beincrypto.com/new-malware-steals-crypto-macos/

2024-08-26 05:43:58

bitcoin
Bitcoin (BTC) $ 91,434.50 4.27%
ethereum
Ethereum (ETH) $ 3,132.67 3.14%
tether
Tether (USDT) $ 1.00 0.09%
solana
Solana (SOL) $ 220.47 6.73%
bnb
BNB (BNB) $ 623.59 1.86%
dogecoin
Dogecoin (DOGE) $ 0.37701 4.36%
xrp
XRP (XRP) $ 0.967205 20.20%
usd-coin
USDC (USDC) $ 1.00 0.01%
staked-ether
Lido Staked Ether (STETH) $ 3,127.46 3.14%
cardano
Cardano (ADA) $ 0.745705 26.99%
tron
TRON (TRX) $ 0.189302 6.81%
shiba-inu
Shiba Inu (SHIB) $ 0.000025 9.17%
avalanche-2
Avalanche (AVAX) $ 34.80 12.04%
the-open-network
Toncoin (TON) $ 5.45 4.58%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 91,232.44 4.00%
wrapped-steth
Wrapped stETH (WSTETH) $ 3,713.17 2.75%
sui
Sui (SUI) $ 3.77 20.47%
pepe
Pepe (PEPE) $ 0.000023 17.69%
weth
WETH (WETH) $ 3,132.01 3.10%
chainlink
Chainlink (LINK) $ 14.18 10.11%
bitcoin-cash
Bitcoin Cash (BCH) $ 433.91 4.70%
polkadot
Polkadot (DOT) $ 5.25 9.76%
near
NEAR Protocol (NEAR) $ 6.08 15.79%
leo-token
LEO Token (LEO) $ 7.75 4.18%
aptos
Aptos (APT) $ 12.37 8.72%
litecoin
Litecoin (LTC) $ 86.10 7.52%
wrapped-eeth
Wrapped eETH (WEETH) $ 3,296.00 2.75%
uniswap
Uniswap (UNI) $ 8.73 10.06%
usds
USDS (USDS) $ 0.996683 0.74%
crypto-com-chain
Cronos (CRO) $ 0.169456 8.04%
stellar
Stellar (XLM) $ 0.15319 16.03%
internet-computer
Internet Computer (ICP) $ 9.00 13.75%
bittensor
Bittensor (TAO) $ 531.83 7.21%
dogwifcoin
dogwifhat (WIF) $ 3.85 12.87%
kaspa
Kaspa (KAS) $ 0.143882 11.25%
ethereum-classic
Ethereum Classic (ETC) $ 23.62 8.24%
fetch-ai
Artificial Superintelligence Alliance (FET) $ 1.31 8.16%
dai
Dai (DAI) $ 1.00 0.01%
whitebit
WhiteBIT Coin (WBT) $ 22.33 0.65%
ethena-usde
Ethena USDe (USDE) $ 1.00 0.17%
bonk
Bonk (BONK) $ 0.000044 31.89%
polygon-ecosystem-token
POL (ex-MATIC) (POL) $ 0.379906 7.49%
hedera-hashgraph
Hedera (HBAR) $ 0.077289 18.04%
blockstack
Stacks (STX) $ 1.93 9.17%
render-token
Render (RENDER) $ 7.24 12.37%
monero
Monero (XMR) $ 144.63 1.64%
okb
OKB (OKB) $ 44.27 2.65%
first-digital-usd
First Digital USD (FDUSD) $ 1.00 0.21%
floki
FLOKI (FLOKI) $ 0.000264 27.71%
filecoin
Filecoin (FIL) $ 4.21 9.77%