logo

Cracked software beats gold: new macOS backdoor stealing cryptowallets

ID: 924a3027-5f35-5ef2-b699-3bd64b47b796

STIX ID: report--924a3027-5f35-5ef2-b699-3bd64b47b796

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2024-01-22

Date Updated: 2026-04-29

Author: Sergey Puzan

...
...

A multi-stage macOS malware campaign distributes a backdoor via repackaged 'cracked' applications: Activator.app solicits admin privileges to run a 'tool' that installs Python, patches target apps, fetches an AES-encrypted Python payload through DNS TXT records, persists with LaunchAgents, provides remote command execution, and replaces or infects cryptocurrency wallets (Exodus, Bitcoin-Qt) to steal seed phrases and wallet data; several C2 domains and IOCs are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.