Recently, the Moonlock Lab cybersecurity team discovered a macOS malware strain that can easily evade detection, posing a significant threat to users’ data privacy and security.
The infection chain for this malware begins when a Mac user visits a website in search of pirated software.
Once the malware infects a macOS computer, it can perform a variety of malicious actions. It collects and stores the Mac owner’s username and sets up temporary directories to hold stolen data before exfiltration. The malware extracts browsing history, cookies, saved passwords, and other sensitive data from web browsers. It also identifies and accesses directories that commonly contain cryptocurrency wallets.
Moonlock Lab has linked this macOS malware to a well-known Russian-speaking threat actor, Rodrigo4. This hacker has been active on the XSS underground forum, where he has been seen recruiting other hackers to help distribute his malware using SEO manipulation and online ads.
This discover
[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.
Read the original article: