Cybersecurity firm Cado Security has identified a new macOS information-stealing malware dubbed “Cthulhu Stealer” that targets Apple users’ credentials and popular cryptocurrency wallets, including MetaMask, Coinbase, Binance, Wasabi, Electrum, Atomic and Blockchain.com wallets. The malware is delivered as an Apple disk image (DMG) and masquerades as legitimate or pirated software such as CleanMyMac or Adobe GenP, tricking users into bypassing macOS Gatekeeper protections and running an unsigned application. Once launched, it uses the macOS osascript mechanism to present a system password prompt, followed by a second prompt for the user’s MetaMask wallet password, then proceeds to seek credentials for other wallets and accounts. After obtaining access, Cthulhu Stealer harvests a broad range of sensitive data, including system information, browser cookies, Telegram data, and passwords stored in iCloud Keychain, using tools such as the open-source Chainbreaker utility. The stolen information is written to files, compressed into an archive and exfiltrated to a command-and-control server, enabling attackers to drain crypto wallets and compromise other accounts. The malware has been offered under a malware-as-a-service model for around $500 per month via Telegram and underground marketplaces, with affiliates deploying it and sharing profits, though the original operator is reported to have gone quiet after disputes and “exit scam” accusations from affiliates. The campaign highlights a growing trend of macOS-focused stealers modeled on earlier tools like Atomic Stealer and underscores that Mac users—particularly those managing digital assets—face increasing risk from social-engineering-based malware and should restrict downloads to trusted sources and avoid running unverified, unsigned apps.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Binance

Comments