Cracked software beats gold: new macOS backdoor stealing cryptowallets
ID: 924a3027-5f35-5ef2-b699-3bd64b47b796
STIX ID: report--924a3027-5f35-5ef2-b699-3bd64b47b796
Feed Name: Securelist by Kaspersky
Threat Score
A multi-stage macOS malware campaign distributes a backdoor via repackaged 'cracked' applications: Activator.app solicits admin privileges to run a 'tool' that installs Python, patches target apps, fetches an AES-encrypted Python payload through DNS TXT records, persists with LaunchAgents, provides remote command execution, and replaces or infects cryptocurrency wallets (Exodus, Bitcoin-Qt) to steal seed phrases and wallet data; several C2 domains and IOCs are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
