A new MacOS attack from malware-as-a-service

August 22, 2024 Cado Security recently exposed a new macOS-targeted malware known as “Cthulhu Stealer,” which operates as malware-as-a-service (MaaS). The malware is designed to steal a wide array of sensitive information, including passwords, cryptocurrency wallets, and browser data. It does so by tricking users into opening a malicious disk image (DMG) file, which then prompts them for credentials using the macOS command-line tool, osascript.

The malware collects and stores the stolen data in a specific directory, creating a zip file that is then sent to a command-and-control (C2) server. The Cthulhu Stealer has been compared to the Atomic Stealer, another macOS infostealer, due to similarities in their functionality and use of osascript. The Cthulhu Stealer was reportedly being sold on malware marketplaces for $500 a month, but complaints from affiliates about unpaid earnings led to the developer being banned from these platforms.

This case highlights the growing threat of malware on macOS, which has traditionally been seen as more secure than other operating systems. Users are advised to be cautious when downloading software, only using trusted sources like the Apple App Store or official developer websites. Additionally, enabling macOS’s built-in security features such as Gatekeeper, keeping systems updated, and using reputable antivirus software can provide extra layers of protection against such threats. This incident serves as a reminder that no system is entirely immune to cyber threats, and vigilance is crucial.

Top Stories

Related Articles

February 5, 2026 A security researcher at Koi named Oren Yomtov has uncovered a widespread malware operation embedded inside an more...

February 4, 2026 More than three million Fortinet devices have been exposed to a critical authentication-bypass vulnerability that is being more...

February 4, 2026 A now-patched security flaw in Docker’s built-in AI assistant exposed users to the risk of remote code more...

January 28, 2026 A suspected credit card skimming attack on the Canada Computers online store may have quietly exposed customer more...

Picture of Jim Love

Jim Love

Jim Love's career in technology spans more that four decades. He's been a CIO and headed a world wide Management Consulting practice. As an entrepreneur he built his own tech business. Today he is a podcast host with the popular tech podcasts Hashtag Trending and Cybersecurity Today with over 14 million downloads. As a novelist, his latest book "Elisa: A Tale of Quantum Kisses" is an Audible best seller. In addition, Jim is a songwriter and recording artist with a Juno nomination and a gold album to his credit. His music can be found at music.jimlove.com
Picture of Jim Love

Jim Love

Jim Love's career in technology spans more that four decades. He's been a CIO and headed a world wide Management Consulting practice. As an entrepreneur he built his own tech business. Today he is a podcast host with the popular tech podcasts Hashtag Trending and Cybersecurity Today with over 14 million downloads. As a novelist, his latest book "Elisa: A Tale of Quantum Kisses" is an Audible best seller. In addition, Jim is a songwriter and recording artist with a Juno nomination and a gold album to his credit. His music can be found at music.jimlove.com

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn