• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M

Cthulhu Stealer: New malware stealing crypto from macOS

user avatar

by Giorgi Kostiuk

2 years ago


  1. Cthulhu Stealer: New threat to macOS
  2. Data stealing methods of Cthulhu Stealer
  3. Pricing and protection strategies

  4. Cado Security has discovered a new malware called Cthulhu Stealer that targets macOS users and steals cryptocurrency from wallets like MetaMask and Binance.

    Cthulhu Stealer: New threat to macOS

    Cado Security has debunked the belief that macOS systems are impervious to malware by discovering a new virus called Cthulhu Stealer. This malware targets macOS users by disguising itself as legitimate applications like CleanMyMac and Adobe GenP, as well as an early release of 'Grand Theft Auto VI.'

    Data stealing methods of Cthulhu Stealer

    Once the malicious DMG file is installed, users enter passwords for the system and MetaMask. The malware then uses osascript to extract passwords from the Keychain. The collected data, including information from wallets like MetaMask, Coinbase, and Binance, is stored in a zip archive identified by the user's country code and the time of the attack. Cthulhu Stealer also targets data from Chrome extension wallets, Minecraft, Wasabi wallet, and other platforms.

    Pricing and protection strategies

    The developers and affiliates of the malware distribute Cthulhu Stealer through Telegram, renting it out for $500 per month. Marketing and advertising are also conducted through specialized platforms. To protect themselves, users are advised to install antivirus software for macOS, avoid suspicious job offers, and regularly update software.

    Cthulhu Stealer highlights the need for enhanced protection of macOS against malware. Users should remain vigilant and adopt modern cybersecurity measures.

0

Rewards

chest
chest
chest
chest

More rewards

Discover enhanced rewards on our social media.

chest

Other news

Security Alert: MEV Bot JaredfromSubwayeth Exploited

chest

A security alert has been issued regarding the MEV bot known as JaredfromSubwayeth, which was exploited on June 26, 2026, raising concerns about the security of MEV bots in the blockchain environment.

user avatarFilippo Romano

Crypto Decouples from Stock Rally as AI Stocks Rise

chest

The SP 500 equal-weight index has reached record highs, while crypto assets have decoupled from the stock market rally, indicating a significant change in market dynamics.

user avatarEmily Carter

New Report Highlights Strict Editorial Policy

chest

A recent report emphasizes the importance of accuracy, relevance, and impartiality in editorial practices.

user avatarTomas Novak

Solana Funding Rate Spreads Indicate Potential Cross-Exchange Arbitrage Opportunities

chest

Traders are observing elevated Solana funding rate spreads as a potential signal for cross-exchange arbitrage amidst market volatility.

user avatarKaterina Papadopoulou

Cardano Whales Increase Accumulation Near Multi-Month Lows

chest

Cardano whale address counts are rising as futures open interest builds, indicating potential shifts in market dynamics.

user avatarMaya Lundqvist

DefiLlama Emphasizes Strict Editorial Policy

chest

A recent report from DefiLlama highlights its strict editorial policy that prioritizes accuracy, relevance, and impartiality in its reporting.

user avatarLeo van der Veen

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.