google-news-img
spot_img
spot_imgspot_imgspot_imgspot_img

How “Cthulhu Stealer” Targets macOS Users and Steals Crypto

  • Cthulhu Stealer targets macOS, stealing crypto wallet data via fake apps.
  • Password Theft: Extracts macOS Keychain and crypto wallet data, and sends it to attackers.
  • MaaS: Rented for $500/month, affiliates spread the malware.

As the valuation of digital assets continues to experience growth, the cryptocurrency domain encounters a proliferation of security-related threats and vulnerabilities.

A recent development in this arena is the emergence of “Cthulhu Stealer,” which represents a particularly advanced iteration of malware-as-a-service (MaaS) that has successfully penetrated macOS systems.

As Cado Security informed readers, Cthulhu Stealer is specifically engineered to compromise macOS platforms to exfiltrate critical cryptocurrency-related data.

Source: Cado Security
Source: Cado Security

Cthulhu Stealer doesn’t come barging in; it sneaks in under the guise of legitimate software. It masquerades as popular applications like CleanMyMac or Adobe GenP. It can even come up as a supposed early release of “Grand Theft Auto VI.”

Users are lured into mounting a malicious DMG file. Once opened, the malware prompts for system and MetaMask passwords, initiating a series of malicious activities.

The malware employs macOS’s own osascript tool to siphon passwords stored in the system’s Keychain. This includes sensitive data from crypto wallets such as MetaMask, Coinbase, and Binance.

The stolen credentials are then packaged into a zip file, which is organized by the victim’s country and attack time, enabling attackers to target their efforts more effectively.

Cthulhu Stealer’s reach extends far beyond just cryptocurrency wallets. It captures:

  • Crypto Wallets: Wasabi, Daedalus, Electrum, Atomic, Harmony, Enjin, Hoo, Dapper, Coinomi, Trust, Blockchain, XDeFi
  • Browser Extensions: Chrome extension wallets
  • Gaming Accounts: Minecraft, Battlenet
  • Miscellaneous Data: Firefox cookies, Telegram Tdata

Additionally, it collects detailed system information, including IP addresses and OS versions. This data is sent to a command and control (C2) server, allowing attackers to refine their tactics and expand their reach.

How Cthulhu Stealer Steals Your Wallet Info

Here’s where it gets unsettling: Cthulhu Stealer isn’t just a tool—it’s a business. Scammers are leasing out this malware for $500 a month. The Cthulhu Team, as the developers are known, profits by renting the malware to affiliates, who then deploy it and earn a portion of the rental fees.

The malware is sold on various malware marketplaces and managed via Telegram, making it easily accessible to those with malicious intent.

Protecting Yourself from Cthulhu Stealer

In light of this new threat, here’s how you can protect yourself:

  1. Install Antivirus Software: Ensure your antivirus is up-to-date and specifically designed for macOS.
  2. Be Wary of Unverified Downloads: Avoid downloading software from unknown sources, especially if linked to urgent or suspicious job offers.
  3. Regular Software Updates: Keep your macOS and applications updated to defend against potential vulnerabilities.

Cthulhu Stealer closely resembles Atomic Stealer, a malware discovered in 2023, suggesting that its creator might have adapted the same code with some tweaks. This malware is being rented out for $500 a month via Telegram, with earnings divided among its affiliates.

Apple has recently acknowledged the rising threat of malware affecting its operating systems. On August 6, the company announced an update for the next macOS version that tightens Gatekeeper protections, making it harder for users to bypass security measures and ensure that only trusted apps can run on their systems.

Back in May, Telegram downplayed concerns about an exploit that let researchers access macOS camera systems, suggesting that the issue was more about Apple’s permission settings rather than flaws within the messaging app itself.

Disclaimer

The contents of this page are intended for general informational purposes and do not constitute financial, investment, or any other form of advice. Investing in or trading crypto assets carries the risk of financial loss. The forecasted data (also called “price prediction”) on this page are subject to change without notice and are not guaranteed to be accurate.

Our Newsletter

Subscribe to our newsletter to get the latest news and promotions.

Arnold Kirimi
Arnold Kirimi
Arnold Kirimi is a crypto and Web3 journalist from Nairobi, Kenya. With a sharp eye for emerging trends and a talent for demystifying blockchain jargon, Kirimi turns complex concepts into compelling narratives. Featured in top outlets like Cointelegraph, DailyCoin and CryptoSlate.