Infostealers Waltz Through macOS to Grab Crypto Wallets, Browser Creds
ID: 07e7284b-d538-5e59-b8bd-40d620a61f50
STIX ID: report--07e7284b-d538-5e59-b8bd-40d620a61f50
Feed Name: Dark Reading
This article analyzes Cthulhu Stealer, a Golang-built macOS infostealer distributed as DMG installers that impersonate legitimate apps (e.g., CleanMyMac, GTA). Once executed, it collects system information and harvests credentials and data from crypto wallets (Coinbase, Binance, Atomic, MetaMask), browser cookies, and game accounts, and it closely mirrors the functionality and code of the widely prevalent Atomic Stealer—raising concerns about enterprise exposure due to limited macOS telemetry and defensive tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
