Mac

MacOS under attack: Cthulhu malware tricks users

The threat of malware for Apple users has increased significantly in recent years. Now security experts are reporting on another program that steals passwords and other data from victims’ computers.

More malware targets Apple devices

Just a week ago, we reported on a malware called Banshee Stealer that steals data such as passwords and browser cookies. Apple users are deceived with a fake password prompt. The malware developed by Cado Security discovered Cthulhu Stealer.

Hidden in DMG files

The malware disguises itself as an Apple Disk Image of a software such as CleanMyMac, Adobe GenP or GTA VI. Once opened by the user, the malware displays a prompt to enter a password using the MacOS command line tool Osa-Script. As with the Banshee Stealer, it states that the system settings must be updated.

As soon as the password has been entered, the malware creates a folder under the path “/User/Shared/NW” in which the keychain passwords, browser cookies or log-ins to crypto exchanges and gaming accounts that are now accessible to it are stored as a text file. The information is then sent to the attackers’ servers as a zip file. The Cthulhu Stealer is offered as malware-as-a-service to individual buyers for a price of 500 US dollars per month via relevant marketplaces on the Internet. It infects both Intel Macs and devices with Apple’s own ARM chips.

How to protect yourself

To protect yourself from the threat or to minimize the risk, the security researchers at Cado Security recommend that all macOS users follow the following advice:

  • Always download software from trusted sources, such as the Apple App Store or the official websites of reputable developers.
  • Enable security features built into macOS, such as Gatekeeper, that prevent the installation of unverified apps.
  • Keep your system and applications up to date with the latest security patches.
  • Use reputable antivirus software to provide additional protection.

Stay alert

Although the security researchers also note that the Cthulhu stealer team no longer seems to be active, the malware once again shows that Apple devices are also at risk from viruses and other malware. Although the view of macOS as an inherently secure system has long persisted, users must be vigilant due to the ever-increasing security threats.

Share
Published by
Yasir Zeb

Recent Posts

5 Lab Methods Scientists Use to Find What’s Really in Tap Water

A glass of tap water reveals little about its chemical makeup. Clear water may still…

3 hours ago

Medical Technology Leadership Programs and Industry Collaborators: The Essential Resource Roundup

In today’s healthcare landscape, collaboration between academic programs and corporate leaders fuels both technological innovation…

1 day ago

Smartphone ban: Italy will soon pay for distracted pedestrians

Italy is cracking down on cell phone use in traffic and will soon be targeting…

1 day ago

Windows 11: Solution for crashing games is distributed automatically

Colorful lights, outdated code and strict anti-cheat software: an unfortunate combination causes massive game crashes…

1 day ago

Plaud One: New in-ear headphones with self-sufficient AI function presented

With the One Explorer Edition, the manufacturer Plaud presents intelligent AI headphones for everyday working…

1 day ago

Can You Trust AI With Your Money? How to Tell a Good Answer From a Confident One

I've written about personal finance for years, and the question readers ask me now has…

1 day ago