HomeTechTech NewsmacOS virus steals iCloud Keychain and browser cookies

macOS virus steals iCloud Keychain and browser cookies

Published on

gaming chair wholesale

Researchers at Cato Networks have discovered a macOS virus that can steal passwords from iCloud Keychain, the location where Macs store their logins. Dubbed Cthulhu Stealer, the malware is a classic Trojan horse that pretends to be a real program to infect your device. The malicious program is still active, even though the group responsible for it no longer exists — it operated as a Malware-as-a-Service.

The virus affects both Macs with Intel processors and models with Apple chips. Among the programs that Cthulhu Stealer impersonates are GTA IV, CleanMyMac and Adobe GenP. This is software that activates Creative Cloud and allows you to use Adobe programs without an activation key.

Malware asks for system password after execution

After the user authorizes the program to run, bypassing the Gatekeeper warning, Cthulhu Stealer asks for the Mac’s password. This allows the malware to access system information and steal data from the iCloud Keychain.

Cthulhu Stealer asked for system password after its execution was released on Gatekeeper (Image: Reproduction/ The Hacker News)
Cthulhu Stealer asked for system password after its execution was released on Gatekeeper (Image: Reproduction/ The Hacker News)

The malware also asks users to enter their MetaMask cryptocurrency wallet password, if they have one. But with access to iCloud KeyChain, hackers can access passwords saved in these wallets, gaming platforms (Steam, Epic) and e-commerce sites. According to Cato Networks, Cthulhu Stealer also captures browser cookies and Telegram information.

Apple and the “sense of security”

macOS Sequoia will have an extra step for users to authorize the execution of apps not approved by Gatekeeper (Image: Reproduction/Apple)
macOS Sequoia will have an extra step for users to authorize the execution of apps not approved by Gatekeeper (Image: Reproduction/Apple)

One of the risks to the spread of the Cthulhu Stealer is the high level of trust among macOS and iOS users in the security of their devices. While Windows and Linux systems are prime targets for hackers, this does not make Macs immune to attacks.

To resolve similar cases, Apple will introduce the good old method of annoying people in macOS Sequoia. If Gatekeeper does not validate the program’s signature, the user will have to open the settings, go to the Privacy and Security menu and then approve the execution of the program.

A simple but very effective solution for those users who don’t want to put in a lot of effort to run any program.

Source(s): 9to5Mac and The Hacker News.

Latest articles

What is DNS? Understand how the internet works behind the scenes

DNS is the acronym for Domain Name System. It is a query system (directory...

With the arrival of iOS 18.1 beta, Apple Intelligence begins to be released

Apple has released the public beta version of iOS 18.1. Typically, minor updates to...

Samsung’s new SSD reaches 4TB and transfers data at 14.5GB/s

The PM9E1 is an SSD from Samsung that takes performance very seriously. The new...

It’s easier to repair the iPhone 16

The iPhone 16 brought new features such as a faster chip and a camera control button,...

Related Posts

With the arrival of iOS 18.1 beta, Apple Intelligence begins to be released

Apple has released the public beta version of iOS 18.1. Typically, minor updates to...

Samsung’s new SSD reaches 4TB and transfers data at 14.5GB/s

The PM9E1 is an SSD from Samsung that takes performance very seriously. The new...

It’s easier to repair the iPhone 16

The iPhone 16 brought new features such as a faster chip and a camera control button,...