logo

MacOS Malware Targets Bitcoin, Exodus Cryptowallets

ID: 441b071c-2828-5d5c-bc89-87d80abf0edf

STIX ID: report--441b071c-2828-5d5c-bc89-87d80abf0edf

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2024-01-23

Date Updated: 2026-04-21

Author: Nathan Eddy, Contributing Writer

...
...

Kaspersky researchers observed a macOS malware campaign (targeting users in the US and Germany) that lures victims with cracked applications, gains root access when users enter admin credentials, replaces legitimate Bitcoin and Exodus wallet apps with backdoored versions, and steals seed phrases and wallet passwords by exfiltrating them to attacker-controlled command-and-control servers; the attackers use DNS TXT records to deliver an encrypted Python second stage and the compromised apps remain operational and persistent on infected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.