https://www.malwarebytes.com/blog/news/2023/04/new-macos-malware-yoinks-a-trove-of-sensitive-information-including-a-users-entire-keychain-database Personal Personal * Security & Antivirus * Free virus removal > * Malwarebytes Premium for Windows > * Malwarebytes Premium for Mac > * Malwarebytes for Chromebook > * Malwarebytes Premium for Android > * Malwarebytes Premium for iOS > * Malwarebytes Premium + Privacy VPN > * AdwCleaner for Windows > * Online Privacy * Malwarebytes Privacy VPN > * Malwarebytes Browser Guard > * How can we help? * Have a current computer infection? Clean your device now * * Try out Malwarebytes Premium, with a full-featured trial Download now * * Find the right solution for you See personal pricing * * Activate, upgrade and manage your subscription in MyAccount Sign in to your account * * Get answers to frequently asked questions and troubleshooting tips Visit our support page Business Business * Solutions * BY COMPANY SIZE * Small Businesses * 1-99 Employees * Mid-size Businesses * 100-999 Employees * Large Enterprise * 1000+ Employees * BY INDUSTRY * Education * Finance * Healthcare * Government * Products * CLOUD-BASED SECURITY MANAGEMENT * Endpoint Protection * Endpoint Protection for Servers * Endpoint Detection & Response * Endpoint Detection & Response for Servers * Incident Response * Nebula Platform Architecture * Mobile Security * CLOUD-BASED SECURITY MODULES * DNS Filtering * Vulnerability & Patch Management * Remediation Connector Solution * Application Block * SECURITY SERVICES * Managed Detection and Response * Cloud Storage Scanning Service * Malware Removal Service * NEXT-GEN ANTIVIRUS FOR SMALL BUSINESS * For Teams * Get Started * + Find the right solution for your business + See business pricing ----------------------------------------------------------------- + Don't know where to start? + Help me choose a product ----------------------------------------------------------------- + See what Malwarebytes can do for you + Get a free trial ----------------------------------------------------------------- + Our sales team is ready to help. Call us now + +1-800-520-2796 Pricing Partners Partners * Explore Partnerships * Partner Solutions * Resellers * Managed Service Providers * Computer Repair * Technology Partners * Contact Us * Partner Success Story * Optimus Systems Logo Marek Drummond Managing Director at Optimus Systems "Thanks to the Malwarebytes MSP program, we have this high-quality product in our stack. It's a great addition, and I have confidence that customers' systems are protected." * See full story Resources Resources * Learn About Cybersecurity * Antivirus * Malware * Ransomware * Malwarebytes Labs - Blog * Glossary * Threat Center * Business Resources * Reviews * Analyst Reports * Case Studies * Press & News * Events * RSA 2021 Featured Event: RSA 2021 * See Event Support Support * Technical Support * Personal Support * Business Support * Premium Services * Forums * Vulnerability Disclosure * Report a False Positive * Product Videos * * Featured Content * Activate Malwarebytes Privacy on Windows device. * See Content FREE DOWNLOAD CONTACT US CONTACT US * Personal Support * Business Support * Talk to Sales * Contact Press * Partner Programs * Submit Vulnerability COMPANY COMPANY * About Malwarebytes * Careers * News & Press SIGN IN SIGN IN * MyAccount: manage your personal/Teams subscription > * Cloud Console: manage your cloud business products > * Partner Portal: management for Resellers and MSPs > [ ] SUBSCRIBE apple logo under a lens Apple | News New macOS malware steals sensitive info, including a user's entire Keychain database Posted: April 3, 2023 by Jovi Umawing MacStealer could be an infamous stealer in the making, but right now, it needs improvement, according to Malwarebytes expert. A new macOS malware--called MacStealer--that is capable of stealing various files, cryptocurrency wallets, and details stored in specific browsers like Firefox, Chrome, and Brave, was discovered by security researchers from Uptycs, a cybersecurity company specializing in cloud security. It can also extract the base64-encoded form of the database of Keychain, Apple's password manager. Users of macOS Catalina (10.5) and versions dependent on Intel, Apple M1, and Apple M2 are affected by this malware. And while MacStealer appears to be the mac malware to watch, it is pretty rudimentary, according to Thomas Reed, Malwarebytes' director of core technology. "There is no persistence method, and it relies on the user opening the app," he adds, considering the foreseeable features the developer wants to add to MacStealer in the future. MacStealer uses channels in Telegram as its command-and-control (C2) center. The malware has been promoted on a dark web forum since the beginning of March. According to the developers, it's still in the early beta stage, thus lacking a builder and panel. These are also why the developers distribute MacStealer as a malware-as-a-service (MaaS), selling at a low price of $100 and promising more advanced features in the future. MacStealer arrives to target macOS systems as an unsigned disk image (.DMG) file. Users are manipulated to download and execute this file onto their systems. Once achieved, a bogus password prompts users in an attempt to steal their real password. MacStealer then saves the password in the affected system's temporary folder (TMP). The malware then proceeds to collect and save the following also within the TMP folder: * Account passwords, browser cookies, and stored credit card details in Firefox, Chrome, and Brave * Cryptocurrency wallets (Binance, Coinomi, Exodus, Keplr Wallet, Martian Wallet, MetaMask, Phantom, Tron, Trust Wallet) * Keychain database in its encoded (base64)form * Keychain password in text format * Various files (.TXT, .DOC, .DOCX, .PDF, .XLS, .XLSX, .PPT, .PPTX, .JPG, .PNG, .CVS, .BMP, .MP3, .ZIP, .RAR, .PY, .DB) * System information in text form MacStealer also compresses everything it stole in a ZIP file and sends it to remote C&C servers for the threat actor to collect later. At the same time, a summary version of the information it stole is sent to pre-configured Telegram channels, alerting the threat actor that new stolen data is available for download. [easset_upload_file13057_262665_e] A data summary of what has been stolen by MacStealer. The threat actors receive this on their personal Telegram bot. (Source: Uptycs) MacStealer being an unsigned DMG file is also a barrier for anyone, especially beginners, attempting to run the program on a modern mac, said Malwarebytes' Reed. "Its attempt at phishing for login passwords is not very convincing and would probably only fool a novice user. But such a user is exactly the type who would have trouble opening it." --------------------------------------------------------------------- Malwarebytes removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below. TRY NOW SHARE THIS ARTICLE --------------------------------------------------------------------- COMMENTS --------------------------------------------------------------------- RELATED ARTICLES --------------------------------------------------------------------- ABOUT THE AUTHOR author Jovi Umawing Senior Content Writer Knows a bit about everything and a lot about several somethings. Writes about those somethings, usually in long-form. Contributors Threat Center Podcast Glossary Scams Write for Labs Cyberprotection for every one. Cybersecurity info you can't do without Want to stay informed on the latest news in cybersecurity? Sign up for our newsletter and learn how to protect your computer from threats. [ ] [] Cyberprotection for every one. FOR PERSONAL Windows Mac iOS Android VPN Connection SEE ALL COMPANY About Us Contact Us Careers News and Press Blog Scholarship Forums FOR BUSINESS Small Businesses Mid-size Businesses Large Enterprise Endpoint Protection Endpoint Detection & Response Managed Detection and Response (MDR) FOR PARTNERS Managed Service Provider (MSP) Program Resellers MY ACCOUNT Sign In SOLUTIONS Free Rootkit Scanner Free Trojan Scanner Free Virus Scanner Free Spyware Scanner Anti Ransomware Protection SEE ALL ADDRESS 3979 Freedom Circle 12th Floor Santa Clara, CA 95054 ADDRESS One Albert Quay 2nd Floor Cork T12 X8N6 Ireland LEARN Malware Hacking Phishing Ransomware Computer Virus Antivirus What is VPN? COMPANY About Us Contact Us Careers News and Press Blog Scholarship Forums MY ACCOUNT Sign In ADDRESS 3979 Freedom Circle, 12th Floor Santa Clara, CA 95054 ADDRESS One Albert Quay, 2nd Floor Cork T12 X8N6 Ireland English Legal Privacy Accessibility Vulnerability Disclosure Terms of Service (c) 2023 All Rights Reserved Select your language