Hackers use fake Ledger apps to steal Mac users’ seed phrases
ID: 77118255-1fb0-51ca-bb90-33f41d433a95
STIX ID: report--77118255-1fb0-51ca-bb90-33f41d433a95
Feed Name: Bleeping Computer
Threat Score
Cybercriminals are deploying fake Ledger Live applications on macOS (notably Odyssey and AMOS, plus PyInstaller-packed trojans) that replace or trojanize the legitimate app, display embedded phishing pages asking for 12/24-word seed phrases, and exfiltrate entered seeds and system/browser data to attacker C2 servers; campaigns have been observed since August 2024 and include Gatekeeper bypasses and copycat activity across underground forums.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
