Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
Home»BITCOIN NEWS»Cybersecurity firm warns Macbook Crypto users targeted by advanced malware attack
BITCOIN NEWS

Cybersecurity firm warns Macbook Crypto users targeted by advanced malware attack

By Crypto FlexsJanuary 24, 20243 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Cybersecurity firm warns Macbook Crypto users targeted by advanced malware attack
Share
Facebook Twitter LinkedIn Pinterest Email

The widespread adoption of cryptocurrencies in the fast-growing cryptocurrency industry is attracting not only legitimate users but also cybercriminals. exploit the vulnerability.

Recent research from cybersecurity firm Kaspersky has uncovered sophisticated malware attacks targeting Macbook users in the cryptocurrency space.

Collect sensitive data from infected Mac systems

Kaspersky Lab Expert discovery The attackers repackaged the pre-cracked application into a package (PKG) file (a type of file format commonly used on Macbooks) and included a Trojan proxy and post-installation script.

Applications containing malicious code were primarily distributed through pirated software channels. When a user attempts to install a cracked application, the infection process begins without their knowledge.

to fool the userThe infected installation package displayed a window with installation instructions, telling it to copy applications to the /Applications/ directory and launch an application called “Activator”.

Activation window and password form targeted at crypto users. Source: Kaspersky

Although it may seem simple at first glance, Activator effectively gave the malware administrator privileges by prompting the user to enter a password.

When executed, the malware checked to see if there was a copy of the programming language installed on the system. python 3 If it wasn’t there, I installed the Python 3 version I copied earlier from my Macbook operating system directory.

The malware then “patched” the downloaded apps by comparing the modified executable to sequences hardcoded inside the Activator. If a match is found, the malware removes the initial bytes, making it appear to the user that the application has been cracked and is working properly. However, as the malware launched its main payload, the attacker’s true intentions were revealed.

Infected samples established communication with a command and control (C2) server by generating a unique Uniform Resource Locator (URL), or web address, through a combination of hardcoded words and a random three-level domain name.

This method allowed the malware to hide its activities within legitimate DNS server traffic and ensure payload download.

that much decrypted script Information obtained from C2 servers, which are remote servers or infrastructure used by cybercriminals to control and manage malware or botnet operations, revealed that the malware operates by executing arbitrary commands received from the server. These commands were often passed as Base64-encoded Python scripts.

The malware also collected sensitive information from the infected system, including operating system version, user directory, list of installed applications, CPU type, and external IP address. The collected data was sent back to the server.

Malware campaign targets cryptocurrency wallet applications

While analyzing the malware campaign, Kaspersky discovered that the C2 server did not return any commands during the investigation and eventually stopped responding.

However, a subsequent attempt to download the Step 3 Python script uncovered an update to the script. metadataThis represents continuous development and adaptation by malware operators.

The malware also included the ability to target popular cryptocurrency wallet applications, including Exodus and Bitcoin-Qt.

When these applications were detected on an infected system, the malware attempted to replace them with infected versions obtained from another host, apple-analyzer (.)com.

Infected cryptocurrency wallets contain mechanisms to steal wallet unlock passwords and secret recovery phrases from unsuspecting users.

The cybersecurity company emphasized that malicious actors continue to distribute cracked applications. To access your computer.

An attacker can easily escalate privileges by abusing user trust during software installation by prompting the user for a password. Kaspersky also highlighted the techniques used by the malware campaign, including storing Python scripts within domain TXT records on DNS servers, demonstrating the attackers’ “ingenuity”.

cryptocurrency
On the daily chart, the overall cryptocurrency market cap fell below $1.5 trillion. Source: TOTAL on TradingView.com

Featured image from Shutterstock, chart from TradingView.com

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Morgan Stanley’s Bitcoin ETF has been a huge success.

July 24, 2026

FTX plans to pay $900 million to creditors when the fifth distribution begins on July 31.

July 18, 2026

Saylor’s strategic message doesn’t help push the Bitcoin story, says StanChart.

July 12, 2026
Add A Comment

Comments are closed.

Recent Posts

Zcash price prediction for 2026: Will $ZEC reach $500 or fall to $200?

July 27, 2026

ORBS) Announces its Participation in World Foundation’s $52.5M funding round as World Shifts From Building the Network to Scaling Utility

July 27, 2026

Bitmine Immersion Technologies (BMNR) Announces ETH Holdings Reach 5.79 Million Tokens, and Total Crypto and Total Cash Holdings of $11.8 Billion

July 27, 2026

EMCD launches Miner Support Program with up to $30M for miners amid industry’s steepest profitability squeeze

July 27, 2026

Korea’s largest bank provides cross-border payment services to Kinexys

July 27, 2026

BitMart closes as BMX prices fall further

July 26, 2026

Licensed Web3 Casinos and Players’ Will

July 25, 2026

Stocks surpass cryptocurrencies in Hyperliquid. ARK says it changes everything

July 25, 2026

AAVE Price Prediction: $100 is the wall. Factors that can destroy or bury a wall include:

July 25, 2026

Morgan Stanley’s Bitcoin ETF has been a huge success.

July 24, 2026

Ethereum price could spark a new uptrend above $1,550.

July 24, 2026

Crypto Flexs is a Professional Cryptocurrency News Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of Cryptocurrency. We hope you enjoy our Cryptocurrency News as much as we enjoy offering them to you.

Contact Us : Partner(@)Cryptoflexs.com

Top Insights

Zcash price prediction for 2026: Will $ZEC reach $500 or fall to $200?

July 27, 2026

ORBS) Announces its Participation in World Foundation’s $52.5M funding round as World Shifts From Building the Network to Scaling Utility

July 27, 2026

Bitmine Immersion Technologies (BMNR) Announces ETH Holdings Reach 5.79 Million Tokens, and Total Crypto and Total Cash Holdings of $11.8 Billion

July 27, 2026
Most Popular

Trader says top 10 altcoins ‘eventually’ poised for 500% surge, updates outlook for Ethereum and Pepe

May 24, 2024

Hong Kong Monetary Authority reports 0.6% increase in total deposits in July 2024

September 1, 2024

Changelog: Version 1.88 – Bitfinex Blog

January 11, 2024
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
© 2026 Crypto Flexs

Type above and press Enter to search. Press Esc to cancel.