Apple Mac Users Warned About ‘Cthulhu Stealer’ Malware Targeting Crypto Wallets

Apple crypto scam
The Cthulhu Stealer malware masquerades as legitimate software.
Author
Author
Ruholamin Haqshanas
About Author

Ruholamin Haqshanas is a contributing crypto writer for CryptoNews. He is a crypto and finance journalist with over four years of experience. Ruholamin has been featured in several high-profile crypto...

Last updated: 
Why Trust Cryptonews
Cryptonews has covered the cryptocurrency industry topics since 2017, aiming to provide informative insights to our readers. Our journalists and analysts have extensive experience in market analysis and blockchain technologies. We strive to maintain high editorial standards, focusing on factual accuracy and balanced reporting across all areas - from cryptocurrencies and blockchain projects to industry events, products, and technological developments. Our ongoing presence in the industry reflects our commitment to delivering relevant information in the evolving world of digital assets. Read more about Cryptonews

Cybersecurity firm Cado Security has warned Apple Mac users regarding a new malware variant named “Cthulhu Stealer,” which is designed to steal personal information and target cryptocurrency wallets.

In a recent report, Cado Security highlighted the growing threat to macOS users.

“While MacOS has a reputation for being secure, macOS malware has been trending up in recent years,” the firm stated.

Cthulhu Stealer Masquerades as Legitimate Software

The Cthulhu Stealer malware masquerades as legitimate software, such as CleanMyMac or Adobe GenP, appearing in the form of an Apple disk image (DMG).

Once users download and open this file, they are prompted to enter their password through macOS’s command-line tool, which runs AppleScript and JavaScript.

After the initial password is entered, the malware prompts for a second password, specifically targeting the Ethereum wallet MetaMask.

Other popular crypto wallets, including those from Coinbase, Wasabi, Electrum, Atomic, Binance, and Blockchain Wallet, are also at risk.

Once Cthulhu Stealer gains access, it stores the stolen data in text files and proceeds to fingerprint the victim’s system, collecting information such as IP address and operating system version.

“The main functionality of Cthulhu Stealer is to steal credentials and cryptocurrency wallets from various stores, including game accounts,” Tara Gould, a researcher at Cado Security, said.

Cthulhu Stealer shares similarities with another piece of malware called Atomic Stealer, which was discovered in 2023 targeting Apple computers.

Gould suggests that the developer behind Cthulhu Stealer likely modified Atomic Stealer’s code to create this new strain.

The malware has been rented out to affiliates for $500 per month through the Telegram messaging platform, with profits shared among the developers.

However, recent disputes over payments have reportedly caused the main scammers to disappear, leading to accusations of an exit scam.

The rise of Cthulhu Stealer and other similar threats, like the AMOS malware that clones Ledger Live software, has prompted Apple to take action.

The tech giant recently announced updates to its macOS, making it more difficult for users to bypass Gatekeeper protections that ensure only trusted applications are run.

Florida Woman Sues Google Over Play Store Crypto Scam

In another incident, Florida resident Maria Vaca has filed a lawsuit against Google, alleging that the tech giant’s negligence led to her losing over $5 million.

The lawsuit argued that she was deceived by a crypto investment app called Yobit Pro, which she downloaded from the Google Play Store.

In April, Google sued two developers for creating 87 fraudulent apps that scammed over 100,000 users, including 8,700 U.S. residents.

Although Yobit Pro was not mentioned in Google’s lawsuit, the tactics described mirror Vaca’s experience.

These include fraudulent apps luring users with promises of high returns, only to demand additional payments under the guise of taxes or fees, with no intention of allowing users to withdraw their funds.

Meanwhile, Google has launched a feature allowing users to search balances of wallets on Bitcoin, Arbitrum, Avalanche, Optimism, Polygon, and Fantom blockchain.

Logo

Why Trust Cryptonews

In the Article
Bitcoin
BTC
$108,231
2.03 %
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors
editors
+ 66 More

Best Crypto ICOs

Discover trending tokens still in presale — early-stage picks with potential

Explore Our Tools

Smart tools made for everyday crypto users

Market Overview

  • 7d
  • 1m
  • 1y
Market Cap
$3,540,240,423,158
4.28
Trending Crypto

More Articles

Blockchain News
Trump’s $TRUMP Coin Gala Under Fire: Lawmakers Push For DOJ Inquiry Ethics of Exclusive Dinner
2025-05-23 22:30:19
Price Analysis
Is Pi Network About to Miss the Bull Run? Insider Selling Raises Major Red Flags (Pi Network Price Prediction)
Alejandro Arrieche
Alejandro Arrieche
2025-05-23 21:14:07
Crypto News in numbers
editors
Authors List + 66 More
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors