logo

Cracked macOS apps drain wallets using scripts fetched from DNS records

ID: fdac94d1-ca73-51cb-82fc-dac85af9e4a4

STIX ID: report--fdac94d1-ca73-51cb-82fc-dac85af9e4a4

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-01-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Kaspersky analyzed a macOS campaign that delivers an information‑stealing backdoor through cracked PKG applications: victims install a trojanized activator which prompts for elevated privileges, runs a Mach‑O loader that fetches base64/AES‑encrypted Python payloads hidden in DNS TXT records using randomized subdomains, installs persistence, and can replace wallet applications (Bitcoin Core, Exodus) with laced versions that exfiltrate seed phrases, passwords and balances to the attacker’s C2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.