Sunday, 23 February 2025
28.8 C
Singapore
32 C
Thailand
23.4 C
Indonesia
26.6 C
Philippines

A new Mac malware threat targets sensitive data

A new Mac malware threat, Cthulhu Stealer, disguises itself as software that targets sensitive data like passwords and crypto wallets.

A recently discovered malware, dubbed “Cthulhu Stealer,” is targeting macOS users by attempting to steal sensitive data, including passwords and cryptocurrency wallets. Cado Security reported this new threat, which disguises itself as legitimate software, making it especially dangerous.

How Cthulhu Stealer operates

Cado Security has provided details on how this malware works. The Cthulhu Stealer arrives as an Apple disk image (.dmg) containing two binaries tailored for different system architectures. Written in Golang, the malware presents itself as genuine software. When users mount the .dmg file, they are prompted to open the software. Once the file is opened, the malware leverages osascript, macOSโ€™s command-line tool for running AppleScript and JavaScript, to prompt the user to enter their password.

Following this initial deception, the malware presents a second prompt asking for the userโ€™s MetaMask password, a tactic seen in other similar malware like Cuckoo, Atomic Stealer, and Banshee Stealer. However, Cthulhu Stealer takes things a step further by gathering system data and attempting to erase usersโ€™ iCloud Keychain passwords through a tool called Chainbreaker.

The disguise that makes it dangerous

Cthulhu Stealer’s ability to masquerade as a well-known software application is particularly concerning. By exploiting Apple’s disk image files, it can appear in popular programs like AdobeGenP, CleanMyMac, and even Grand Theft Auto IV. The AdobeGenP application, for instance, is known to allow users to bypass entering a serial key or paying for a Creative Cloud subscription, making it an attractive target for unsuspecting users.

Once Cthulhu Stealer has infiltrated your system, it collects a wide range of data, including Telegram account information and web browser cookies. This data is then compressed into a ZIP archive and sent to a command-and-control (C2) server where the attackers operate. Interestingly, the malware shares some features with Atomic Stealer, including similar spelling errors, suggesting that the developer might have reused code with slight modifications.

Staying safe in a rising-threat landscape

To protect yourself from this growing threat, you must be vigilant about where you download your software. Stick to reputable sources and ensure your Mac always runs the latest macOS version. Adding a legitimate antivirus program for Macs is also a wise precaution.

Apple is aware of the increasing threat of Mac malware and has responded by implementing crucial security updates. With the release of macOS Sequoia, Apple has removed the ability to override Gatekeeper by Control-clicking on software that isnโ€™t properly signed or notarized. To further secure your system, youโ€™ll need to go to System Settings > Privacy & Security to check the security information of any software before running it.

Hot this week

OPPO Find N5 review: A foldable experience refined

OPPO Find N5 features a lightweight design, AI-powered enhancements, a large immersive display, fast charging capabilities, and a long-lasting battery.

DJIโ€™s RS 4 Mini stabiliser now features advanced subject tracking

DJIโ€™s RS 4 Mini stabiliser introduces subject tracking, improved battery life, and better handling, making it an excellent tool for content creators.

Apple’s first foldable iPhone might not look like a Galaxy Z Fold

Appleโ€™s foldable iPhone may not resemble Samsungโ€™s Z Fold. A wider design and later launch are expected.

Snow Bros. makes a comeback with its first new game in almost 30 years

Snow Bros. Wonderland returns to the classic franchise after nearly 30 years, featuring 3D gameplay, multiplayer co-op, and new challenges. It is now available.

Elon Muskโ€™s xAI unveils Grok 3, its most advanced AI model yet

xAI, Elon Muskโ€™s AI company, has launched Grok 3, its latest AI model. It features improved reasoning, new research tools, and expanded subscription plans.

BT and Equinix expand partnership to enhance global interconnectivity

BT and Equinix expand their partnership to boost interconnectivity for multinational businesses, deploying BTโ€™s Global Fabric NaaS in 40+ Equinix data centres worldwide.

LG unveils new SKS branding for luxury kitchen suite at KBIS 2025

LG rebrands Signature Kitchen Suite to SKS at KBIS 2025, introducing new luxury appliances like a free-zone induction range and an advanced island system.

LG unveils advanced laundry solutions at KBIS 2025

LG unveils its latest heat pump washer and dryer lineup at KBIS 2025, featuring AI-driven efficiency, ventless design, and smart connectivity.

The Vision Pro is now easier to share, and getting a new iPhone app

Appleโ€™s Vision 2.4 update makes sharing the Vision Pro easier, introduces a new iPhone app for content discovery, and adds the Spatial Gallery app.

Related Articles