HomeSecurityGmera Trojan malware targets Mac users

Gmera Trojan malware targets Mac users

Mac users are being targeted by a new campaign – the Gmera Trojan malware – that aims to remove crypto from their wallets.

Trojanized cryptocurrency trading software and apps designed for Apple's operating system were recently detected by ESET researchers, who detailed their findings in a publication on Thursday.

Trojanized applications are offered online as versions of legitimate trading software, such as those developed by Kattana, an organization that has created a desktop terminal application cryptocurrency trading.

Gmera Trojan malware

ESET is not sure of the exact attack vector, but it appears that social engineering is the method used to reach users. In fact, in March, Kattana published a warning stating that users were approached with the aim of downloading applications with malware. Copycat websites claiming to be versions of Kattana were also detected.

"It is very likely that the operators are directly contacting their targets to convince them to install the malicious application," the researchers say.

Four rebranded versions of the legitimate Kattana app have been identified – called Cointrazer, Cupatrade, Licatrade and Trezarus – which facilitate trading, but also include a Gmera installer embedded in the software.

Researchers from Trend Micro published an analysis of Gmera in 2019. The malware was previously found in another Mac trading app called Stockfolio.

When executed, Gmera first connects to a command and control center (C2) via HTTP and then connects remote terminal sessions to another C2 via a hardcoded IP address.

Using the Licatrade sample as a basis for analysis – although there are slight variations within each brand type – ESET noted that a shell script is deployed to establish the C2 connection, as well as to maintain persistence by installing a Launch Agent.

However, the Launch Agent is broken in Licatrade. The attackers intended to launch a shell script from the victim's machine to a server they would control, but in other versions of the Trojanized application, the persistence mechanism works.

Much of Kattana's legitimate terminal remained intact, including a login required by the app to connect wallets and transactions – a feature that fraudsters can take advantage of to gain access to victims' wallets.

During the identification stage, the malware will pull data from the computer and display available Wi-Fi, as honeypots will likely disable this form of connection. Gmera will also scan for virtual machines and take a screenshot to see which version of macOS is being used.

The operators intended to skip this check if Catalina is installed as users have to approve screenshots or audio recordings every time – and so if the check went through, it would raise suspicion. However, bugs in the malware’s code mean that regardless of the operating system, the screenshot is taken.

Then the data theft begins. Shell scripts are used to extract browser cookies, browser history, and wallet credentials.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS