As the valuation of digital assets continues to experience growth, the cryptocurrency domain encounters a proliferation of security-related threats and vulnerabilities.
A recent development in this arena is the emergence of “Cthulhu Stealer,” which represents a particularly advanced iteration of malware-as-a-service (MaaS) that has successfully penetrated macOS systems.
As Cado Security informed readers, Cthulhu Stealer is specifically engineered to compromise macOS platforms to exfiltrate critical cryptocurrency-related data.

Cthulhu Stealer doesn’t come barging in; it sneaks in under the guise of legitimate software. It masquerades as popular applications like CleanMyMac or Adobe GenP. It can even come up as a supposed early release of “Grand Theft Auto VI.”
Users are lured into mounting a malicious DMG file. Once opened, the malware prompts for system and MetaMask passwords, initiating a series of malicious activities.
The malware employs macOS’s own osascript tool to siphon passwords stored in the system’s Keychain. This includes sensitive data from crypto wallets such as MetaMask, Coinbase, and Binance.
The stolen credentials are then packaged into a zip file, which is organized by the victim’s country and attack time, enabling attackers to target their efforts more effectively.
Cthulhu Stealer’s reach extends far beyond just cryptocurrency wallets. It captures:
- Crypto Wallets: Wasabi, Daedalus, Electrum, Atomic, Harmony, Enjin, Hoo, Dapper, Coinomi, Trust, Blockchain, XDeFi
- Browser Extensions: Chrome extension wallets
- Gaming Accounts: Minecraft, Battlenet
- Miscellaneous Data: Firefox cookies, Telegram Tdata
Additionally, it collects detailed system information, including IP addresses and OS versions. This data is sent to a command and control (C2) server, allowing attackers to refine their tactics and expand their reach.
How Cthulhu Stealer Steals Your Wallet Info
Here’s where it gets unsettling: Cthulhu Stealer isn’t just a tool—it’s a business. Scammers are leasing out this malware for $500 a month. The Cthulhu Team, as the developers are known, profits by renting the malware to affiliates, who then deploy it and earn a portion of the rental fees.
The malware is sold on various malware marketplaces and managed via Telegram, making it easily accessible to those with malicious intent.
Protecting Yourself from Cthulhu Stealer
In light of this new threat, here’s how you can protect yourself:
- Install Antivirus Software: Ensure your antivirus is up-to-date and specifically designed for macOS.
- Be Wary of Unverified Downloads: Avoid downloading software from unknown sources, especially if linked to urgent or suspicious job offers.
- Regular Software Updates: Keep your macOS and applications updated to defend against potential vulnerabilities.
Cthulhu Stealer closely resembles Atomic Stealer, a malware discovered in 2023, suggesting that its creator might have adapted the same code with some tweaks. This malware is being rented out for $500 a month via Telegram, with earnings divided among its affiliates.
Apple has recently acknowledged the rising threat of malware affecting its operating systems. On August 6, the company announced an update for the next macOS version that tightens Gatekeeper protections, making it harder for users to bypass security measures and ensure that only trusted apps can run on their systems.
Back in May, Telegram downplayed concerns about an exploit that let researchers access macOS camera systems, suggesting that the issue was more about Apple’s permission settings rather than flaws within the messaging app itself.









