竊資軟體Cthulhu Stealer鎖定macOS用戶電子錢包、帳號密碼而來
支付動態 · 2024-08-26

Cthulhu Stealer曾冒充硬碟清理工具CleanMyMac、遊戲軟體Grand Theft Auto IV以及Adobe GenP等合法軟體,來誘騙macOS用戶下載

Cado Security

MacOS平臺向來被認為比較少惡意軟體,但現今已漸漸吸引駭客注意力。資安業者Cado Security發現一款惡意程式Cthulhu Stealer,專門鎖定macOS電腦用戶竊取密碼、cookies或其他敏感資訊。

Cthulhu Stealer(或簡稱Cthulhu)為一惡意程式即服務(malware-as-a-service,MaaS),是由一個代號Cthulhu或Balaclavv的用戶在Telegram頻道及二個暗網交易市集兜售,以每月500美元提供服務,由其開發人員和同夥向macOS用戶發動攻擊。Cthulhu是2023年底現身,並在今年頭幾個月內開始活動。

Cthulhu本身是一種Apple磁碟映像檔(DMG檔),視架構而定,可附加於2種二進位檔。它以GoLang寫成,可偽裝成合法軟體。研究人員發現它曾經冒充過合法軟體如硬碟清理工具CleanMyMac、遊戲軟體Grand Theft Auto IV以及Adobe GenP,誘使用戶下載。

一旦用戶下載安裝.dmg檔,它會要求用戶開啟檔案,並啟動macOS的指令行工具osascript就會接連要求用戶輸入它想竊取的敏感資訊,包括cookies、帳號或電子錢包密碼。研究人員歸納Cthulhu的竊取目標包含Chrome與Firefox瀏覽器cookies、Telegram密碼、Apple Keychain、SafeStorage、Minecraft帳號以及十多種電子錢包應用如Chrome Extension Wallet、MetaMask、XDeFI、Coinbase或Blockchain Wallet等等。

研究人員並公布了Cthulhu的Yara偵測規則,以及該惡意程式安裝時會在用戶電腦/Users/Shared/NW路徑下建立資料夾。

Cthulhu是資安專家發現最新一隻攻擊Mac電腦用戶的竊密程式。從早期的KeRanger和Silver Sparrow開始逐漸增多。今年資安業者SentinelOne發現竊資軟體KeySteal、Atomic Stealer、CherryPie,都能繞過macOS作業系統的防護機制XProtect竊取用戶敏感資料。

Popular articles
Are you ready to maximize your earnings? Try ProPush.me Constructor!
Marketing
Institutional Academy that exceeded expectations marked the opening of GAT CDMX
Online Game
1spin4win grows its Latin American presence by partnering with Fortuna Juegos
Online Game
Indiana online casino bill stalls in House committee
Regulation
1spin4win releases unique slot Don Catleone Hold and Win featuring gangster cats
Online Game
Kazakhstan plans to penalise online casino promotions
Regulation
Brazil Proposes Raising Gambling Tax Rate to 24%, With Revenue Allocated to Social Security and Healthcare
Regulation
GAT Expo Puerto Rico Will Pulse with the New Era of Gaming in the Caribbean
Marketing
Vietnam's tightening online gaming policy creates new market opportunities
Southeast Asia
JILI Partners with Cricket Legend AB de Villiers (ABD) to Launch Exclusive Branded Game Series 100% 11
Sports Game
Across 6 Cities: HUIDU Invites You to 8 World Cup Parties Redefining High-Value Social Networking
HUIDU Focus
B2B Tech Infrastructure Gains Momentum in Philippine Gaming Sector
Southeast Asia
Super PAC Raises $48 Million: Sports Betting Forces Ramp Up Political Push
Regulation
GGC Awards 2026 Shines in Colombo: Honoring Leaders and Innovators in the iGaming Industry
HUIDU Focus
Gaming & Technology Expo Makes a Powerful Entrance in CDMX
Marketing
Home
Game
Cooperation
Find
My