Mac Users Cautioned About Malware Stealing Crypto Wallets

2 min read | August 26, 2024 06:20 AM BST | By Team Kalkine Media

A new strain of malware named “Cthulhu Stealer” is posing a significant threat to Apple Mac users, particularly those using popular {Cryptocurrency} wallets. This malware targets widely used wallets such as MetaMask, Coinbase, Wasabi, Electrum, Atomic, Binance, and Blockchain Wallet on macOS operating systems. 

According to cybersecurity firm Cado Security, the malware exploits a common misconception that macOS systems are largely immune to malware threats. As reported on August 22, Cthulhu Stealer operates by leveraging the macOS command-line tool to prompt users for their passwords. After obtaining the system password, the malware requests the password for cryptocurrency wallets, leading to theft of sensitive information. 

Cthulhu Stealer collects stolen data in text files and proceeds to gather additional information about the victim’s system, including IP address and operating system version. The primary function of this malware is to extract credentials and cryptocurrency wallet data, including information related to game accounts, as explained by Cado researcher Tara Gould. 

The malware bears similarities to Atomic Stealer, which was identified in 2023 targeting Apple computers. This suggests that Cthulhu Stealer’s developer likely adapted the code from Atomic Stealer. The malware was reportedly rented out to affiliates for a subscription fee via the Telegram messaging platform, with the main developer sharing profits from successful deployments. However, recent disputes over payments have led to accusations of an exit scam by these affiliates, leaving the malware’s operators inactive. 

On August 23, Cointelegraph reported the emergence of another malware, AMOS, which also targets Mac users by cloning Ledger Live software, heightening concerns about malware threats on macOS. 

In response to increasing malware threats, Apple has taken steps to enhance security. On August 6, Apple announced updates to its next-generation macOS version, making it more challenging for users to override Gatekeeper protections that control the execution of trusted applications. 

This development underscores the growing need for vigilance and robust security practices among macOS users, particularly those handling sensitive financial and personal data. 


Disclaimer

The content, including but not limited to any articles, news, quotes, information, data, text, reports, ratings, opinions, images, photos, graphics, graphs, charts, animations and video (Content) is a service of Kalkine Media Limited, Company No. 12643132 (Kalkine Media, we or us) and is available for personal and non-commercial use only. Kalkine Media is an appointed representative of Kalkine Limited, who is authorized and regulated by the FCA (FRN: 579414). The non-personalised advice given by Kalkine Media through its Content does not in any way endorse or recommend individuals, investment products or services suitable for your personal financial situation. You should discuss your portfolios and the risk tolerance level appropriate for your personal financial situation, with a qualified financial planner and/or adviser. No liability is accepted by Kalkine Media or Kalkine Limited and/or any of its employees/officers, for any investment loss, or any other loss or detriment experienced by you for any investment decision, whether consequent to, or in any way related to this Content, the provision of which is a regulated activity. Kalkine Media does not intend to exclude any liability which is not permitted to be excluded under applicable law or regulation. Some of the Content on this website may be sponsored/non-sponsored, as applicable. However, on the date of publication of any such Content, none of the employees and/or associates of Kalkine Media hold positions in any of the stocks covered by Kalkine Media through its Content. The views expressed in the Content by the guests, if any, are their own and do not necessarily represent the views or opinions of Kalkine Media. Some of the images/music/video that may be used in the Content are copyright to their respective owner(s). Kalkine Media does not claim ownership of any of the pictures displayed/music or video used in the Content unless stated otherwise. The images/music/video that may be used in the Content are taken from various sources on the internet, including paid subscriptions or are believed to be in public domain. We have used reasonable efforts to accredit the source wherever it was indicated or was found to be necessary.


Sponsored Articles


Investing Ideas

Previous Next