Skip to main content

This Mac malware can steal your credit card data in seconds

Despite their reputation for security, Macs can still get viruses, and that’s just been proven by a malicious new Mac malware that can steal your credit card info and send it back to the attacker, ready to be exploited. It’s a reminder to be careful when opening apps from unknown sources.

The malware, dubbed MacStealer, was discovered by Uptycs, a threat research firm. It hoovers up a wide array of your personal data, including the iCloud Keychain password database, credit card data, cryptocurrency wallet credentials, browser cookies, documents, and more. That means there’s a lot that could be at risk if it gains a foothold on your Mac.

Related Videos
A fake password prompt created by the MacStealer macOS malware.
A fake password prompt created by the MacStealer macOS malware. Uptycs

MacStealer begins its attacks using an installer file called weed.dmg. Opening this launches a fake password prompt that harvests your login credentials and uses them to access your sensitive information, which is then zipped up and sent to a server controlled by the hacker. Once that’s done, the stolen data is broadcasted to interested parties on a dedicated Telegram channel.

Fortunately, even though MacStealer can extract your Mac’s iCloud Keychain database, it isn’t able to extract the passwords stored within. That’s because iCloud Keychain encrypts any data it stores. As the attackers note, without a user’s master password, getting at those passwords is “almost impossible.”

How to protect yourself

Apple's Craig Federighi speaking about macOS security at WWDC 2022.

Right now, the malware’s developers are selling it for $100 per build, making it relatively affordable in the world of malware as a service. According to the developer, the low price is due to the malware lacking a user panel and any builder functionality, as well as its current beta status.

Unfortunately, it seems like the threat actor developing MacStealer has some more ideas that they are planning to incorporate into future versions. That includes a cryptocurrency wallet drainer, a user control panel, the ability for customers to generate new builds themselves, and more.

If you want to protect yourself from MacStealer (and other Mac malware), you should keep your Mac up to date with the latest patches from Apple and only allow the installation of apps from trusted sources (such as the official App Store). Installing an antivirus app would also be a good idea, as would using one of the best password managers to keep your sensitive data locked up and encrypted.

Editors' Recommendations

How Unreal Engine 5 is tackling the biggest problem in PC gaming
unreal engine 5 tackling biggest problem pc graphics respec

During its State of Unreal address at GDC 2023, Epic announced a wide-ranging suite of features for Unreal Engine 5.2. But perhaps the most important feature coming in the updated engine doesn't relate to lighting, geometry detail, or ray tracing. It's all about performance.

Unreal Engine games, rightly or wrongly, have been associated with stuttering and hitches over the past few years. With the new release, Epic is finally tackling the problem head-on, so I thought it was high time to break down why Unreal games so commonly show stutter, what Epic is doing to solve the problem, and when we can expect to see those efforts show up in new releases.
Remember the stutter
These frame time spikes manifest as severe stutters in Gotham Knights.

Read more
Some Apple staff concerned about its high-tech headset, report claims
A rendering of an Apple mixed-reality headset (Reality Pro) in a gray color seen from the front.

Apple is expected to launch its first mixed-reality headset in the next few months, but a report by the New York Times on Sunday suggests that some at the company have doubts about its potential for success.

Citing eight current and former Apple employees, the Times said that for some at the company, “enthusiasm has given way to skepticism” regarding the AR/VR headset, which is likely to be unveiled at Apple’s annual Worldwide Developers Conference (WWDC) in June.

Read more
Apple’s Reality Pro headset just got demoed in a secret ceremony
A rendering of four Apple mixed-reality headsets (Reality Pro) in various colors sitting on a surface.

Apple’s mysterious Reality Pro headset just hit a major milestone last week when it was demonstrated in a large-scale ceremony to around 100 of the company’s top executives. That’s encouraging, as showing it off to so many high-ranking employees suggests the device is almost ready for launch.

The revelation comes from Mark Gurman’s weekly Power On newsletter, wherein the Bloomberg journalist explained that the event marks a notable turning point in the mixed-reality headset’s development ahead of its anticipated launch at Apple’s Worldwide Developers Conference (WWDC) in June.

Read more