• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M

Dangerous Cthulhu Stealer Malware Threatens Mac Users

user avatar

by Giorgi Kostiuk

2 years ago


  1. How Cthulhu Stealer Works
  2. Consequences of Infection
  3. Connection with Other Malware

  4. A new malware called “Cthulhu Stealer” poses a significant risk to Apple Mac users by stealing personal data and cryptocurrency wallets.

    How Cthulhu Stealer Works

    “Cthulhu Stealer” disguises itself as legitimate software such as CleanMyMac and Adobe GenP, tricking users into downloading it. The malware is delivered as an Apple Disk Image (DMG) file. When opened, it uses the macOS command-line tool to prompt users for their passwords. Once the password is entered, the malware then asks for access to cryptocurrency wallets like MetaMask, a popular Ethereum wallet, as well as other major wallets such as those from Coinbase, Binance, and Blockchain Wallet.

    Consequences of Infection

    The stolen information is saved in text files and includes data like IP addresses and operating system versions. The primary function of “Cthulhu Stealer” is to collect credentials, cryptocurrency wallets, and even gaming accounts. The malware shows a significant increase in attacks on macOS, supported by Cado Security researcher Tara Gould.

    Connection with Other Malware

    “Cthulhu Stealer” shares characteristics with the malware “Atomic Stealer,” identified in 2023, indicating that its developer may have used the same code with some modifications. Moreover, the malware was rented out for $500 per month through Telegram, with profits shared among affiliates. However, disputes among the scammers have reportedly led to accusations of an exit scam, causing the operation to go inactive.

    Malware like “Cthulhu Stealer” continues to evolve, posing a serious threat to Mac users' data security. Users should be extremely cautious when downloading software from unreliable sources and follow cybersecurity recommendations.

0

Rewards

chest
chest
chest
chest

More rewards

Discover enhanced rewards on our social media.

chest

Other news

Bitcoin Tests Global Liquidity Assumptions

chest

Bitcoin is currently testing the assumption that rising global liquidity will lead to higher prices, as global M2 liquidity reaches a record high.

user avatarLeo van der Veen

Switzerland to Host US-Iran Memorandum Signing on June 19, 2026

chest

Switzerland is set to host a US-Iran memorandum signing on June 19, 2026, involving Qatar and Pakistan as mediators.

user avatarLi Weicheng

Aztec Connect Smart Contract Exploited for $219 Million

chest

A deprecated Aztec Connect smart contract has been exploited for about $219 million, highlighting the risks associated with old contracts in DeFi.

user avatarAisha Farooq

World Liberty Financial Partners with UFC for USD1 Stablecoin Bonus Pool

chest

World Liberty Financial has partnered with UFC to use its USD1 stablecoin in the event's bonus structure, aiming to promote the token to a mainstream sports audience.

user avatarTenzin Dorje

Binance Reaffirms Commitment to EU Operations Amid License Concerns

chest

Binance has stated its intention to continue serving EU customers despite potential license issues.

user avatarBayarjavkhlan Ganbaatar

Rep. Thomas Massie's Federal Reserve Abolition Act Gains Attention in Bitcoin Community

chest

Rep. Thomas Massie's proposal to abolish the Federal Reserve is gaining traction in Bitcoin circles due to its connection to 'The Bitcoin Standard'.

user avatarMohamed Farouk

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.