Crypto Wallets At Risk: Mac Users Targeted By Sneaky Malware

bitcoinist发布于2024-08-26更新于2024-08-26

文章摘要

Recent reports emerge showing infections in Mac computers—particularly from active crypto users. Two striking presence of malware in this case...

Recent reports emerge showing infections in Mac computers—particularly from active crypto users. Two striking presence of malware in this case are the Banshee Stealer and the Cthulhu Stealer, developed to deceive users into transferring sensitive information, more like passwords and credentials to cryptocurrency wallets.

The Banshee Stealer, as detected by Elastic Labs, is potent malware with various functions. It collects sensitive information, such as browsing history, cookies, and login information from applications like Microsoft Edge, Google Chrome, Mozilla Firefox, as well as numerous cryptocurrency wallets such as Electrum and Coinomi.

The malware uses several deceiving techniques, like streamlining the fraudulent password-prompt view to stimulate real system behavior for a better trap of the real password from the innocent user. It can also check the main working language and does not infect the computer if it is set to Russian.

Cthulhu Stealer Malware

First spotted a few months ago, the Cthulhu Stealer is marketed as malware-for-hire for a measly $500 per month. Usually, this Trojan will masquerade as a piece of legitimate software, which it tricks users into downloading and installing, typically under the name CleanMyMac or Adobe GenP.

Total crypto market cap currently at $2.1 trillion. Chart: TradingView

The said malware variant runs on both Intel and Apple Silicon Macs. After the first launch, it will request the user’s system password and then the MetaMask wallet password. On the victim’s machine, it scrapes massive personal data, from iCloud Keychain entries to cookies of various web browsers, and sends these to a command-and-control server.

Protecting Crypto Against Malware Threats

Users have to be extremely careful with downloading software and they should only install it from trusted locations. Verify the authenticity of applications before installation. Enabling security features, such as keeping macOS up to date with the latest security patches and using antivirus software, can provide improved protection.

Image: The KR Group

As an additional measure, they suggest the practice of reviewing internet accounts periodically in order to detect intrusion and the use of strong, unique passwords, as well as two-factor authentication where possible.

The company is now fighting back against such threats with new, improved security within macOS Sequoia, which will no longer allow users to open software that lacks the right signature or isn’t notarized just by Control-clicking on it to bypass Gatekeeper.

Instead, they will have to proceed into System Settings and view the security information about it before using the software. With malware for Macs becoming one of the fastest in development, especially in relation to cryptocurrency, vigilance and proactive security practice become very vital in the protection of personal data.

Traditionally, Macs have been considered the less vulnerable machines compared with the Windows peers, but the recent past, which has seen attacks surge in, is a pointer to the fact that no system is completely safe. Staying informed and embracing proper security practices will significantly enhance resilience to such emerging threats for all Mac users.

Featured image from Pexels, chart from TradingView

Christian Encila

Christian Encila

Christian, a journalist and editor with leadership roles in Philippine and Canadian media, is fueled by his love for writing and cryptocurrency. Off-screen, he's a cook and cinephile who's constantly intrigued by the size of the universe.

你可能也喜欢

互联网资本市场2026:美国结构性转变与亚洲机构的战略窗口

互联网资本市场2026:美国结构性转变与亚洲机构的战略窗口 本文认为,新技术产业发展通常经历实验、过热、监管介入和产业形成四个阶段。加密行业已度过实验与过热期(如ICO、DeFi浪潮),在经历FTX事件等洗牌后,正进入监管介入与产业形成的交汇阶段。 美国监管进展显著,如《GENIUS法案》明确了稳定币地位,SEC和CFTC将SOL等资产确认为数字商品。机构采用加速,链上代币化资产(RWA)和稳定币总规模已近3000亿美元。 文章提出“互联网资本市场”概念,即资产的发行、交易和结算在单一公链上实时完成(T+0),以智能合约替代传统中介,消除结算延迟和隐性成本。美国正引领此变革。 Solana被视为该市场的具体实现,其高吞吐、低费用和Token-2022标准(内置合规功能)满足了机构需求。摩根大通、道富银行、花旗、Visa等多家美国大型金融机构已在Solana上开展真实交易或概念验证,案例覆盖债券发行、贸易融资、全球汇款、资产代币化等多个领域。 监管格局部分确立(如数字商品分类、稳定币规则),但前沿领域如股票代币化、DEX监管等仍有待立法(如《CLARITY法案》)。 对于亚洲机构而言,战略窗口在于作为“快速跟随者”,借鉴美国已验证的基础设施和监管框架。可根据本地监管成熟度分阶段执行:监管明确地区(如新加坡、香港)可立即商业化;监管过渡地区(如韩国)应提前搭建运营结构;监管探索地区则需保持小规模实验能力。 结论指出,互联网资本市场已成为运行中的现实。机构选择基于实际的技术与合规需求,而非偏好。亚洲机构的决策关键不再是“是否进入”,而是“以何种顺序和切入点进入”。当前“验证已完成但标准未固化”的区间,正是可利用的战略窗口,但其持续时间不确定。

marsbit26分钟前

互联网资本市场2026:美国结构性转变与亚洲机构的战略窗口

marsbit26分钟前

交易

现货
活动图片