Researchers at Trend Micro have discovered a new Mac Trojan that aims to steal user information. The Trojan deceives users by posing as a legitimate trading application.
The Trojan.MacOS.GMERA software is presented as the Mac-based Stockfolio application. In reality, it contains scriptsthat enable malicious activities. So far, two versions of the malware have been detected.
The first version is a ZIP file, containing an app bundle (Stockfoli.app) and a hidden encrypted file (.app).
When the file is executed, the trading application appears on the screen . However, at the same time, the application executes shell scripts in the Resources directory
The first script steals various information, such as IP addresses, applications, operating system installation date, disk information, graphics/display information, wireless network , and screenshots.

Once the data is collected, it is encoded and stored in a hidden file. It is then sent to the hackers ' server .
The second script copies other files, decrypts some of them or even deletes them . In addition, it performs other malicious activities.
The second version of the malware is much simpler. It uses a copy of Stockfolio version 1.4.13 to hide its malicious activity. It only runs a script that steals usernames and IP addresses and sends them to the hackers.
Furthermore, it allows hackers to execute commands on the infected computer, installing various files and creating a reverse shell (on ports 25733-25736) on the command and control server.
Trend Micro researchers have noticed that the malware has changed a lot in recent times. The original version is quite different from the current one. Malware administrators have simplified the process, while at the same time adding more features. Hackers can do much more damage to victims' computers and more easily than before. Researchers believe that the hackers behind the Trojan are trying to make the malware even more effective and dangerous.
