logo

"Activator" Alert: MacOS Malware Hides in Cracked Apps, Targeting Crypto Wallets

ID: 5d3ed0f5-77f9-5976-be48-74b0722eb2f6

STIX ID: report--5d3ed0f5-77f9-5976-be48-74b0722eb2f6

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-01-23

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Activator is an actively maintained macOS backdoor distributed through cracked software DMGs that tricks users into granting administrator privileges, then uses a novel DNS TXT-based C2 mechanism to fetch encrypted scripts and payloads; the malware can run arbitrary commands, persist, and replace crypto wallet applications (Exodus, Bitcoin Core) with trojanized versions that steal seed phrases and wallet credentials, and has been observed at scale across hundreds of infected Mach-O binaries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.