• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
"activator" alert: macos malware hides in cracked apps, targeting crypto

“Activator” Alert: MacOS Malware Hides in Cracked Apps, Targeting Crypto Wallets

You are here: Home / General Cyber Security News / “Activator” Alert: MacOS Malware Hides in Cracked Apps, Targeting Crypto Wallets
January 23, 2024

Cracked computer software have been noticed infecting Apple macOS consumers with a beforehand undocumented stealer malware capable of harvesting process details and cryptocurrency wallet info.

Kaspersky, which discovered the artifacts in the wild, explained they are designed to focus on machines running macOS Ventura 13.6 and later on, indicating the malware’s capability to infect Macs on both of those Intel and Apple silicon processor architectures.

The attack chains leverage booby-trapped disk picture (DMG) data files that include things like a software named “Activator” and a pirated version of respectable software program these as xScope.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Consumers who stop up opening the DMG information are urged to go both of those data files to the Purposes folder and operate the Activator element to use a meant patch and operate the xScope app.

Cybersecurity

Launching Activator, on the other hand, displays a prompt inquiring the sufferer to enter the program administrator password, thereby permitting it to execute a Mach-O binary with elevated permissions in buy to launch the modified xScope executable.

“The trick was that the destructive actors experienced taken pre-cracked software variations and extra a number of bytes to the starting of the executable, as a result disabling it to make the user launch Activator,” security researcher Sergey Puzan stated.

The future stage involves developing get in touch with with a command-and-control (C2) server to fetch an encrypted script. The C2 URL, for its element, is created by combining text from two tough-coded lists and incorporating a random sequence of five letters as a 3rd-stage domain identify.

Crypto Wallets

A DNS request for this domain is then despatched to retrieve a few DNS TXT records, each and every made up of a Base64-encoded ciphertext fragment that is decrypted and assembled to assemble a Python script, which, in switch, establishes persistence and functions as a downloader by reaching out to “apple-health and fitness[.]org” just about every 30 seconds to download and execute the most important payload.

“This was a fairly appealing and abnormal way of getting in touch with a command-and-management server and hiding action inside site visitors, and it certain downloading the payload, as the response message arrived from the DNS server,” Puzan described, describing it as “seriously ingenious.”

The backdoor, actively managed and current by the threat actor, is created to operate obtained instructions, obtain program metadata, and check for the existence of Exodus and Bitcoin Main wallets on the contaminated host.

Cybersecurity

If uncovered, the programs are replaced by trojanized variations downloaded from the area “apple-analyser[.]com” that are equipped to exfiltrate the seed phrase, wallet unlock password, identify, and balance to an actor-controlled server.

“The last payload was a backdoor that could run any scripts with administrator privileges, and substitute Bitcoin Core and Exodus crypto wallet apps put in on the machine with infected versions that stole magic formula restoration phrases the moment the wallet was unlocked,” Puzan explained.

The growth will come as cracked application is progressively becoming a conduit to compromise macOS end users with a wide variety of malware, which includes Trojan-Proxy and ZuRu.

Observed this write-up exciting? Adhere to us on Twitter  and LinkedIn to read through far more special information we publish.


Some elements of this post are sourced from:
thehackernews.com

Previous Post: «from megabits to terabits: gcore radar warns of a new From Megabits to Terabits: Gcore Radar Warns of a New Era of DDoS Attacks
Next Post: Malicious NPM Packages Exfiltrate Hundreds of Developer SSH Keys via GitHub malicious npm packages exfiltrate hundreds of developer ssh keys via»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.