Security researchers have discovered a new info-stealer malware, dubbed Cthulhu Stealer , designed to target Apple Mac computers

Cthulhu Stealer is offered as malware-as-a-service (MaaS) for $500 per month, starting in late 2023. It is capable of targeting both x86_64 and Arm architectures.
"Cthulhu Stealer is an Apple disk image (DMG) that comes with two binaries, depending on the architecture," said Tara Gould, a researcher at Cato Security.
The malware is written in Golang and disguises itself as legitimate software (e.g. CleanMyMac, Grand Theft Auto IV , and Adobe GenP).
See also: TodoSwift: New macOS malware – Is it linked to North Korean hackers?
Users who end up opening the unsigned file, after allowing it to execute bypassing Gatekeeper, are prompted to enter their system password.
In the next step, a second prompt appears to enter the MetaMask password . Cthulhu Stealer is also designed to collect system information and iCloud Keychain passwords using an open source tool called Chainbreaker.
The above, as well as other stolen data, such as browser cookies and Telegram account information , is compressed and stored in a ZIP file and then sent to a command and control (C2) server.
“The primary function of the Cthulhu Stealer malware is to steal credentials and cryptocurrency wallets from various stores, including gaming accounts,” Gould said.
See also: New macOS Sequoia strengthens Gatekeeper controls
“The functionality and features of Cthulhu Stealer are very similar to Atomic Stealer, indicating that the developer of Cthulhu Stealer likely took Atomic Stealer and modified the code.“.
The hackers behind the macOS malware are said to be no longer active, in part due to payment disputes that led to accusations (by affiliates) of exit scams. As a result, the main developer has been banned from the cybercrime marketplace used to advertise the malware.
Cthulhu Stealer doesn't have anything special compared to other info-stealer malware circulating on the dark web market. However, it can be effective.
See also: BeaverTail: New version of macOS malware discovered
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

macOS malware protection
Apple offers some built-in security features, such as Gatekeeper and XProtect to prevent infection.
But there are some other methods of protection:
- Keep your operating system and software up to date to patch any known vulnerabilities
- Be cautious when downloading and opening attachments or files from unknown sources
- Use a reliable antivirus software, especially if you frequently download files from the Internet.
- Enable FileVault, which encrypts your data and protects it in case of theft or unauthorized access.
- Regularly back up your important files to an external hard drive
Source: thehackernews.com
