MacOS Malware Targets Bitcoin, Exodus Cryptowallets
ID: 441b071c-2828-5d5c-bc89-87d80abf0edf
STIX ID: report--441b071c-2828-5d5c-bc89-87d80abf0edf
Feed Name: Dark Reading
Kaspersky researchers observed a macOS malware campaign (targeting users in the US and Germany) that lures victims with cracked applications, gains root access when users enter admin credentials, replaces legitimate Bitcoin and Exodus wallet apps with backdoored versions, and steals seed phrases and wallet passwords by exfiltrating them to attacker-controlled command-and-control servers; the attackers use DNS TXT records to deliver an encrypted Python second stage and the compromised apps remain operational and persistent on infected systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
