logo

Infostealers Waltz Through macOS to Grab Crypto Wallets, Browser Creds

ID: 07e7284b-d538-5e59-b8bd-40d620a61f50

STIX ID: report--07e7284b-d538-5e59-b8bd-40d620a61f50

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2024-08-22

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

This article analyzes Cthulhu Stealer, a Golang-built macOS infostealer distributed as DMG installers that impersonate legitimate apps (e.g., CleanMyMac, GTA). Once executed, it collects system information and harvests credentials and data from crypto wallets (Coinbase, Binance, Atomic, MetaMask), browser cookies, and game accounts, and it closely mirrors the functionality and code of the widely prevalent Atomic Stealer—raising concerns about enterprise exposure due to limited macOS telemetry and defensive tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.