Wednesday, 30 April 2025
26.8 C
Singapore
30.9 C
Thailand
21.9 C
Indonesia
29.2 C
Philippines

A new Mac malware threat targets sensitive data

A new Mac malware threat, Cthulhu Stealer, disguises itself as software that targets sensitive data like passwords and crypto wallets.

A recently discovered malware, dubbed “Cthulhu Stealer,” is targeting macOS users by attempting to steal sensitive data, including passwords and cryptocurrency wallets. Cado Security reported this new threat, which disguises itself as legitimate software, making it especially dangerous.

How Cthulhu Stealer operates

Cado Security has provided details on how this malware works. The Cthulhu Stealer arrives as an Apple disk image (.dmg) containing two binaries tailored for different system architectures. Written in Golang, the malware presents itself as genuine software. When users mount the .dmg file, they are prompted to open the software. Once the file is opened, the malware leverages osascript, macOS’s command-line tool for running AppleScript and JavaScript, to prompt the user to enter their password.

Following this initial deception, the malware presents a second prompt asking for the user’s MetaMask password, a tactic seen in other similar malware like Cuckoo, Atomic Stealer, and Banshee Stealer. However, Cthulhu Stealer takes things a step further by gathering system data and attempting to erase users’ iCloud Keychain passwords through a tool called Chainbreaker.

The disguise that makes it dangerous

Cthulhu Stealer’s ability to masquerade as a well-known software application is particularly concerning. By exploiting Apple’s disk image files, it can appear in popular programs like AdobeGenP, CleanMyMac, and even Grand Theft Auto IV. The AdobeGenP application, for instance, is known to allow users to bypass entering a serial key or paying for a Creative Cloud subscription, making it an attractive target for unsuspecting users.

Once Cthulhu Stealer has infiltrated your system, it collects a wide range of data, including Telegram account information and web browser cookies. This data is then compressed into a ZIP archive and sent to a command-and-control (C2) server where the attackers operate. Interestingly, the malware shares some features with Atomic Stealer, including similar spelling errors, suggesting that the developer might have reused code with slight modifications.

Staying safe in a rising-threat landscape

To protect yourself from this growing threat, you must be vigilant about where you download your software. Stick to reputable sources and ensure your Mac always runs the latest macOS version. Adding a legitimate antivirus program for Macs is also a wise precaution.

Apple is aware of the increasing threat of Mac malware and has responded by implementing crucial security updates. With the release of macOS Sequoia, Apple has removed the ability to override Gatekeeper by Control-clicking on software that isn’t properly signed or notarized. To further secure your system, you’ll need to go to System Settings > Privacy & Security to check the security information of any software before running it.

Hot this week

Ghost of Yotei is set to launch on PS5 this October with a new trailer and details

Ghost of Yotei arrives on PS5 this October with a new trailer, a thrilling story, and multiple game editions, including exclusive extras.

Lian Li’s new Lancool 207 Digital case brings a 6-inch LCD screen to your PC

Lian Li's Lancool 207 Digital PC case brings a bright 6-inch LCD screen to your setup, offering style, function, and full customisation.

Gitex Asia x Ai Everything Singapore highlights robotics, AI and next-gen tech at inaugural event

Gitex Asia x Ai Everything Singapore highlights robotics, AI, startups, and tech innovations, shaping Southeast Asia’s digital future.

Step inside Brooklyn’s cardboard coworking space for AI chatbots

Step inside Chat Haus, a clever cardboard coworking space for AI chatbots in Brooklyn. It offers a playful take on the future of creativity.

Veeam report reveals nearly 70% of organisations still targeted by ransomware

Nearly 70% of organisations were hit by ransomware last year, says Veeam, urging stronger recovery strategies and proactive resilience.

Apple’s AirPods Pro dropped to their lowest price of the year so far

Apple’s latest AirPods Pro with USB-C are now just US$169—this year’s best price and only US$16 more than their Black Friday price.

Apple creates a new celebrity hub to showcase stars across its platforms

Apple has quietly launched a new website to help you explore celebrity content across its TV, Music, and Podcasts apps.

Content moderators around the world join forces to demand better conditions

Content moderators form a global alliance to demand better working conditions and mental health support from Big Tech companies.

Electric vehicle sales in Singapore surge, making up 4 in 10 cars sold in early 2025

In early 2025, EVs made up 40% of new car sales in Singapore, driven by tax breaks, rising demand, and strong sales from Chinese brands.

Related Articles

Popular Categories