Beware! New Malware Cthulhu Stealer Targets Apple Mac Users, Aiming at Cryptocurrency Wallets
Publication Time:2024-08-26 12:01:12
Apple Mac users have been warned about a new type of malware called 'Cthulhu Stealer,' revealed by cybersecurity firm Cado Security. Although macOS has long been considered relatively secure, Cado Security notes that the number of malware targeting macOS has increased in recent years. 'Cthulhu Stealer' appears as an Apple Disk Image (DMG) and cleverly disguises itself as legitimate software such as CleanMyMac and Adobe GenP. When users inadvertently open these files, macOS command-line tools used to execute AppleScript and JavaScript will prompt for a password. Once the user provides the password, the malware proceeds to request the password for the Ethereum wallet MetaMask. Additionally, it targets other popular cryptocurrency wallets, including those from Coinbase, Wasabi, Electrum, Atomic, Binance, and Blockchain Wallet. After obtaining this information, 'Cthulhu Stealer' stores the stolen data in a text file and further collects IP addresses and operating system versions for system fingerprinting. Tara Gould, a researcher at Cado, explains that the main function of 'Cthulhu Stealer' is to steal credentials from various stores and cryptocurrency wallets, including gaming accounts. However, it has been reported that the scammer behind this malware has ceased operations.
malware
Cthulhu Stealer
Cryptocurrency Wallets
Apple Mac
Data Theft