Tuesday, 1 April 2025
26.4 C
Singapore
29.2 C
Thailand
26 C
Indonesia
27.2 C
Philippines

A new Mac malware threat targets sensitive data

A new Mac malware threat, Cthulhu Stealer, disguises itself as software that targets sensitive data like passwords and crypto wallets.

A recently discovered malware, dubbed “Cthulhu Stealer,” is targeting macOS users by attempting to steal sensitive data, including passwords and cryptocurrency wallets. Cado Security reported this new threat, which disguises itself as legitimate software, making it especially dangerous.

How Cthulhu Stealer operates

Cado Security has provided details on how this malware works. The Cthulhu Stealer arrives as an Apple disk image (.dmg) containing two binaries tailored for different system architectures. Written in Golang, the malware presents itself as genuine software. When users mount the .dmg file, they are prompted to open the software. Once the file is opened, the malware leverages osascript, macOSโ€™s command-line tool for running AppleScript and JavaScript, to prompt the user to enter their password.

Following this initial deception, the malware presents a second prompt asking for the userโ€™s MetaMask password, a tactic seen in other similar malware like Cuckoo, Atomic Stealer, and Banshee Stealer. However, Cthulhu Stealer takes things a step further by gathering system data and attempting to erase usersโ€™ iCloud Keychain passwords through a tool called Chainbreaker.

The disguise that makes it dangerous

Cthulhu Stealer’s ability to masquerade as a well-known software application is particularly concerning. By exploiting Apple’s disk image files, it can appear in popular programs like AdobeGenP, CleanMyMac, and even Grand Theft Auto IV. The AdobeGenP application, for instance, is known to allow users to bypass entering a serial key or paying for a Creative Cloud subscription, making it an attractive target for unsuspecting users.

Once Cthulhu Stealer has infiltrated your system, it collects a wide range of data, including Telegram account information and web browser cookies. This data is then compressed into a ZIP archive and sent to a command-and-control (C2) server where the attackers operate. Interestingly, the malware shares some features with Atomic Stealer, including similar spelling errors, suggesting that the developer might have reused code with slight modifications.

Staying safe in a rising-threat landscape

To protect yourself from this growing threat, you must be vigilant about where you download your software. Stick to reputable sources and ensure your Mac always runs the latest macOS version. Adding a legitimate antivirus program for Macs is also a wise precaution.

Apple is aware of the increasing threat of Mac malware and has responded by implementing crucial security updates. With the release of macOS Sequoia, Apple has removed the ability to override Gatekeeper by Control-clicking on software that isnโ€™t properly signed or notarized. To further secure your system, youโ€™ll need to go to System Settings > Privacy & Security to check the security information of any software before running it.

Hot this week

Google Pixel 9a arrives in Singapore this April for S$799

The Google Pixel 9a launches in Singapore in April 2025 with a Tensor G4 chip, 48MP camera, and seven years of updates, starting at S$799.

Character AI introduces parental supervision tools for teen safety

Character AI introduces parental supervision tools, offering weekly reports on teen activity to enhance safety while maintaining user privacy.

Samsung Galaxy A06 5G offers modern features at an affordable S$228

The Samsung Galaxy A06 5G, with a 50MP camera and 5,000mAh battery, launches in Singapore on March 21, 2025, for S$228.

US expands trade blacklist to block Chinaโ€™s access to computing technology

The US expands its trade blacklist, adding 80 firms to block China from obtaining advanced computing technology for military use.

Xbox titles lead PlayStation Store preorders

Xbox games dominate PS5 preorders, with Indiana Jones and Forza Horizon 5 leading sales, proving Microsoft's strategy works.

This tiny and affordable device upgrades any speaker with Wi-Fi streaming and hi-res audio

The Atonemo Streamplayer is a tiny, affordable device that adds Wi-Fi streaming and hi-res audio support to any speaker with a 3.5mm aux port.

Apple prepares for M5 iPad Pro and MacBook Pro release

Apple is set to launch the M5 iPad Pro and MacBook Pro in late 2024, with the M6 models expected to introduce an in-house modem in 2027.

MacBook Pro design overhaul expected in 2026

Apple might release a long-awaited MacBook Pro redesign in 2026, with OLED screens, improved portability, and more features.

Chinese EV makers urged to expand globally despite tariff challenges

Chinese EV makers are urged to expand globally despite rising tariffs. Industry experts stress the need for overseas production and strategic partnerships.

Related Articles