Apple Mac users have been warned about a new piece of malware called "Cthulhu Stealer" that can steal users' personal information and target crypto wallets.
A few days ago, cybersecurity company Cado Security said: "For years, it has been widely believed that macOS systems are immune to malware. Although MacOS is known for its security, related malware has been on the rise in recent years."
It is reported that "Cthulhu Stealer" appears in the form of an Apple disk image (DMG) and is disguised as legitimate software such as CleanMyMac and Adobe GenP. When the user opens the file, the macOS command-line tools for running AppleScript and JavaScript prompt the user for a password.
Once entered, a second prompt will appear to enter the password for the Ethereum wallet MetaMask. It also targets other popular crypto wallets, including those from Coinbase, Wasabi, Electrum, Atomic, Binance, and Blockchain Wallet.
The malware stores the stolen data in text files and then fingerprints the victim's system to collect data such as IP address and operating system version.
"Cthulhu Stealer's primary function is to steal credentials and cryptocurrency wallets from various stores, including gaming accounts," explained Cado researcher Tara Gould. However, the scammers allegedly behind the malware are no longer active. (Cointelegraph)