A new MacOS attack from malware-as-a-service

August 22, 2024 Cado Security recently exposed a new macOS-targeted malware known as “Cthulhu Stealer,” which operates as malware-as-a-service (MaaS). The malware is designed to steal a wide array of sensitive information, including passwords, cryptocurrency wallets, and browser data. It does so by tricking users into opening a malicious disk image (DMG) file, which then prompts them for credentials using the macOS command-line tool, osascript.

The malware collects and stores the stolen data in a specific directory, creating a zip file that is then sent to a command-and-control (C2) server. The Cthulhu Stealer has been compared to the Atomic Stealer, another macOS infostealer, due to similarities in their functionality and use of osascript. The Cthulhu Stealer was reportedly being sold on malware marketplaces for $500 a month, but complaints from affiliates about unpaid earnings led to the developer being banned from these platforms.

This case highlights the growing threat of malware on macOS, which has traditionally been seen as more secure than other operating systems. Users are advised to be cautious when downloading software, only using trusted sources like the Apple App Store or official developer websites. Additionally, enabling macOS’s built-in security features such as Gatekeeper, keeping systems updated, and using reputable antivirus software can provide extra layers of protection against such threats. This incident serves as a reminder that no system is entirely immune to cyber threats, and vigilance is crucial.

Top Stories

Related Articles

May 20, 2026 The Cybersecurity and Infrastructure Security Agency, the arm of the U.S. government tasked with protecting critical infrastructure more...

May 11, 2026 Instructure has restored access to its Canvas learning platform after a cyberattack disrupted service for universities and more...

May 6, 2026 The official White House mobile app for iOS and Android is facing scrutiny after a security researcher more...

May 4, 2026 Microsoft Defender mistakenly detected legitimate DigiCert root certificates as malware, triggering widespread false-positive alerts and, in some more...

Picture of Jim Love

Jim Love

Jim Love's career in technology spans more that four decades. He's been a CIO and headed a world wide Management Consulting practice. As an entrepreneur he built his own tech business. Today he is a podcast host with the popular tech podcasts Hashtag Trending and Cybersecurity Today with over 14 million downloads. As a novelist, his latest book "Elisa: A Tale of Quantum Kisses" is an Audible best seller. In addition, Jim is a songwriter and recording artist with a Juno nomination and a gold album to his credit. His music can be found at music.jimlove.com
Picture of Jim Love

Jim Love

Jim Love's career in technology spans more that four decades. He's been a CIO and headed a world wide Management Consulting practice. As an entrepreneur he built his own tech business. Today he is a podcast host with the popular tech podcasts Hashtag Trending and Cybersecurity Today with over 14 million downloads. As a novelist, his latest book "Elisa: A Tale of Quantum Kisses" is an Audible best seller. In addition, Jim is a songwriter and recording artist with a Juno nomination and a gold album to his credit. His music can be found at music.jimlove.com

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn