MetaStealer malware targets Apple macOS in recent attacks
A new information stealer malware named MetaStealer has turned its attention to Apple macOS, making it the latest in a growing list of information stealer families targeting the operating system following Stealer, Pureland, Atomic Stealer, and Realst.
See also: Sri Lankan government emails lost after massive ransomware attack

In these attacks, MetaStealer is distributed in the form of fake application bundles in disk image format (DMG), with targets approached via threats posing as candidate design clients in order to share a password-protected ZIP file containing the DMG file.
In other cases, the malicious code is disguised as Adobe files or installers for Adobe Photoshop. Evidence gathered so far shows that MetaStealer's footprints began appearing in the wild in March 2023. The most recent sample was uploaded to VirusTotal on August 27, 2023.
The main component of the package is an encrypted Go-based executable file, which has capabilities to collect data from iCloud Keychain, saved passwords, and files from the compromised system.
See also: MGM Resorts: Major systems out of service due to “cybersecurity incident”
Selected versions of the malware have been observed that potentially target Telegram and Meta.
SentinelOne reported that it has observed some variants of MetaStealer pretending to be the TradingView platform, the same tactic that Atomic Stealer in recent weeks.
This opens up two possibilities: either the same malware authors may be behind both stealer families and have been adopted by different hackers due to differences in the delivery mechanism, or they are the result of distinct groups of perpetrators.
“The emergence of yet another macOS infostealer this year shows that the trend of targeting Mac users for their data continues to grow in popularity among hackers,” said Phil Stokes of SentinelOne.
See also: Pegasus spyware: CISA warns about iPhone security
What makes MetaStealer notable among this new category of malware is its clear targeting of business users and its purpose of sending valuable information from keychains and other sources from these targets. Such high-value data can be used to conduct additional cybercriminal activities or gain access to a larger corporate network.
Information source: thehackernews.com
