A new infostealer has been observed targeting Catalina and newer versions of macOS running on Intel M1 and M2 CPUs. Shilpesh Trivedi, a security researcher at Uptycs, explained the findings in an advisory published Friday.
“Uptycs’ threat research team discovered a macOS stealer. […] We control its operation via Telegram,” Trivedi wrote. “We named it MacStealer.”
The infostealer was discovered during the company’s dark web hunting campaign. This malware can extract information from documents, his browser cookies (Firefox, Google Chrome, Brave) and login information.
Learn more about cookies here. France fined her $64 million to Microsoft and imposed advertising cookies on Bing users.
“Malicious actors use .DMG files to spread malware. When users run the file, they get a fake password prompt to harvest passwords,” Trivedi explains.
The stealer was then observed creating a ZIP archive of the stolen data and sending it to the command and control (C2) infrastructure via POST requests using Python user agent commands. It ends the attack chain by deleting the data and her ZIP file from the victim’s system.
“At the same time, MacStealer will send selected information to the listed Telegram channels,” said Trivedi. “If you send the compiled ZIP file to the C2, the C2 will share it with the attacker’s personal girlfriend’s Telegram bot.”
The Uptycs team looked at MacStealer’s VirusTotal charts and found several different malware samples. Threat actors among infostealers also appear to be actively working on new feature updates, including cryptocurrency theft, reverse shelling, and more.
“Distributors were found to be taking mass production orders for MacStealer from other attackers, so the malware could spread more widely,” warns Trivedi.
To protect themselves from this threat, security researchers have determined that users should keep their Mac systems up-to-date and have the “Allow apps downloaded from the App Store/App Store and identified developers” setting allowed. recommended that you only allow installation of files from trusted sources that you trust.
MacStealer’s discovery comes weeks after Trellix security researchers discovered a new privilege escalation bug class on both macOS and iOS.
Editorial image credit: Tada Images / Shutterstock.com