Cracked macOS apps drain wallets using scripts fetched from DNS records
ID: fdac94d1-ca73-51cb-82fc-dac85af9e4a4
STIX ID: report--fdac94d1-ca73-51cb-82fc-dac85af9e4a4
Feed Name: Bleeping Computer
Kaspersky analyzed a macOS campaign that delivers an information‑stealing backdoor through cracked PKG applications: victims install a trojanized activator which prompts for elevated privileges, runs a Mach‑O loader that fetches base64/AES‑encrypted Python payloads hidden in DNS TXT records using randomized subdomains, installs persistence, and can replace wallet applications (Bitcoin Core, Exodus) with laced versions that exfiltrate seed phrases, passwords and balances to the attacker’s C2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
