By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Sécurité Helvétique News | AmyrisSécurité Helvétique News | AmyrisSécurité Helvétique News | Amyris
  • Home
  • Compliance
    Compliance
    Show More
    Top News
    McDonald’s Delaware Court Decision Will Change CCO World Forever
    21 February 2023
    Health Equity: Board Directors’ Most Important ESG Measure
    7 May 2023
    News Roundup: 75% of US Companies Mention Climate Risk in 10-Ks
    15 June 2024
    Latest News
    How 2025 Redefined Telemarketing Compliance
    1 December 2025
    Advice for the AI Boom: Use the Tools, Not Too Much, Stay in Charge
    25 November 2025
    Strange Bedfellows: How a Supreme Court Ruling Found Its Perfect Match in the Trump Administration
    19 November 2025
    Where in the Loop? Testing AI Across 120 Compliance Tasks to Find Out Where Humans Are Most Needed
    13 November 2025
  • Cyber Security
    Cyber Security
    Show More
    Top News
    Pro-Iranian Hacker Group Targeting Albania with No-Justice Wiper Malware
    6 January 2024
    Chinese Hackers Exploit Zero-Day Flaws in Ivanti Connect Secure and Policy Secure
    11 January 2024
    GitHub Rotates Keys After High-Severity Vulnerability Exposes Credentials
    17 January 2024
    Latest News
    North Korean Hackers Target Developers with Malicious npm Packages
    30 August 2024
    Russian Hackers Exploit Safari and Chrome Flaws in High-Profile Cyberattack
    29 August 2024
    Vietnamese Human Rights Group Targeted in Multi-Year Cyberattack by APT32
    29 August 2024
    2.5 Million Reward Offered For Cyber Criminal Linked To Notorious Angler Exploit Kit
    29 August 2024
  • Technology
    Technology
    Show More
    Top News
    Samsung Galaxy S24, Galaxy S24+, Galaxy S24 Ultra: Specs, Release Date, Price, Features
    17 January 2024
    Microsoft “Fix it” available to mitigate Internet Explorer 8 vulnerability | MSRC Blog
    21 January 2024
    Realm of Satan Brings Dark Glamour to a Misunderstood Culture
    25 January 2024
    Latest News
    Why XSS still matters: MSRC’s perspective on a 25-year-old threat  | MSRC Blog
    9 September 2025
    Microsoft Bug Bounty Program Year in Review: $13.8M in Rewards | MSRC Blog
    28 August 2025
    Microsoft Bounty Program Year in Review: $16.6M in Rewards  | MSRC Blog
    27 August 2025
    postMessaged and Compromised | MSRC Blog
    26 August 2025
  • Businness
    Businness
    Show More
    Top News
    Has Donald Trump abandoned Ukraine?
    20 May 2025
    99 Speed Mart’s Southeast Asia 500 debut is the latest milestone for the company and its founder, a childhood polio survivor
    21 June 2025
    China 'clearly' trying to interfere in Taiwan's democracy, Taipei says before recall vote
    23 July 2025
    Latest News
    AI labs like Meta, Deepseek, and Xai earned worst grades possible on an existential safety index
    6 December 2025
    Visa is moving its European headquarters to London’s Canary Wharf, FT reports
    5 December 2025
    Client Challenge
    4 December 2025
    Binance names cofounder Yi He as new co-CEO
    3 December 2025
  • ÉmissionN
    Émission
    Cyber Security Podcasts
    Show More
    Top News
    Stream episode Cybercrime Wire For Mar. 1, 2024. Golden Corral Falls Victim To A Data Breach. WCYB Digital Radio. by Cybercrime Magazine podcast
    3 March 2024
    Cybercrime News For Feb. 27, 2024. MicroStrategy's X Hacked for Crypto Scam. WCYB Digital Radio.
    11 March 2024
    Cybercrime News For Mar. 18, 2024. NFPrompt Reports Losses to Cyberattack. WCYB Digital Radio.
    19 March 2024
    Latest News
    Stream episode Cybercrime Magazine Update: Cybercrime In India. Sheer Volume Overwhelming Police Forces. by Cybercrime Magazine podcast
    3 March 2025
    Autonomous SOC. Why It’s A Breakthrough For The Mid-Market. Subo Guha, SVP of Product, Stellar Cyber
    2 March 2025
    Cyber Safety. Protecting Families From Smart Toy Risks. Scott Schober, Author, "Hacked Again."
    2 March 2025
    Cybercrime News For Feb. 25, 2025. Hackers Steal $49M from Infini Crypto Fintech. WCYB Digital Radio
    2 March 2025
Search
Cyber Security
  • Application Security
  • Darknet
  • Data Protection
  • network vulnerability
  • Pentesting
Compliance
  • LPD
  • RGPD
  • Finance
  • Medical
Technology
  • AI
  • MICROSOFT
  • VERACODE
  • CHECKMARKX
  • WITHSECURE
  • Amyris
  • Contact
  • Disclaimer
  • Privacy Policy
  • About us
© 2023 Sécurité Helvétique NEWS par Amyris Sarl. Tous droits réservés
Reading: newly-discovered malware steals passwords and exfiltrates data from infected Macs • Graham Cluley
Share
Sign In
Notification Show More
Font ResizerAa
Sécurité Helvétique News | AmyrisSécurité Helvétique News | Amyris
Font ResizerAa
  • Home
  • Compliance
  • Cyber Security
  • Technology
  • Business
Search
  • Home
    • Compliance
    • Cyber Security
    • Technology
    • Businness
  • Legal Docs
    • Contact us
    • Disclaimer
    • Privacy Policy
    • About us
Have an existing account? Sign In
Follow US
  • Amyris
  • Contact
  • Disclaimer
  • Privacy Policy
  • About us
© 2023 Sécurité Helvétique par Amyris Sarl.
Sécurité Helvétique News | Amyris > Blog > Cyber Security > newly-discovered malware steals passwords and exfiltrates data from infected Macs • Graham Cluley
Cyber Security

newly-discovered malware steals passwords and exfiltrates data from infected Macs • Graham Cluley

webmaster
Last updated: 2023/04/20 at 10:41 PM
webmaster
Share
3 Min Read
SHARE

I’m still encountering people who, even after all these years, believe that their Apple Mac computers are somehow magically invulnerable to ever being infected by malware.

This is despite the fact that malware has been infecting different incarnations of Apple computer for even longer than PCs, that macro malware often doesn’t care what operating system you’re using, that there are firms who had over 25 years’ worth of success developing anti-virus software for Macs, and that even Apple itself has been releasing updates to MacOS’s built-in anti-virus defences since 2009.

Yes, there’s a lot lot more malware for PCs than Macs, but that doesn’t mean that the problem doesn’t exist at all. And you may feel very smug not running any type of anti-virus on your Mac, but you’ll probably have the smile wiped off your face if you come a cropper.

Email Sign up to our newsletter
Security news, advice, and tips.

With that in mind, it’s worth sharing that boffins at Uptycs shared details of some newly-discovered macOS malware last month, that they have dubbed “MacStealer.”

According to Uptypcs, MacStealer is being distributed on dark web forums for as little as $100 as a tool for stealing the passwords, cookies, and credit card details from Google, Firefox, and Chrome browsers. In addition, the malware can steal Keychain data, and umpteen different types of data files (including documents, spreadsheets, presentations, images, databases, and archives) – sending exfiltrated data back to hackers via Telegram.

Despite MacStealer’s author claiming it is a “first beta version”, it is said to support Intel as well as M1 and M2 Macs, and works on macOS 10 (Catalina) to the latest macOS 13 (Ventura).

According to Uptycs, the malware is being spread in a fairly rudimentary way. Running a boobytrapped .DMG file can cause a fake System Preferences prompt to appear that asks for the user’s password.

Macstealer dmg

Once the hackers have your computer’s password, your problems are going to get a whole lot worse.

There’s no indication that MacStealer is in widespread use by cybercriminals, but regardless it makes sense to protect your computer – whatever operating system you choose to run.

Found this article interesting? Follow Graham Cluley on Twitter or Mastodon to read more of the exclusive content we post.


Graham Cluley is a veteran of the anti-virus industry having worked for a number of security companies since the early 1990s when he wrote the first ever version of Dr Solomon’s Anti-Virus Toolkit for Windows. Now an independent security analyst, he regularly makes media appearances and is an international public speaker on the topic of computer security, hackers, and online privacy.
Follow him on Twitter at @gcluley, on Mastodon at @[email protected], or drop him an email.

You Might Also Like

North Korean Hackers Target Developers with Malicious npm Packages

Russian Hackers Exploit Safari and Chrome Flaws in High-Profile Cyberattack

Vietnamese Human Rights Group Targeted in Multi-Year Cyberattack by APT32

2.5 Million Reward Offered For Cyber Criminal Linked To Notorious Angler Exploit Kit

Unpatched AVTECH IP Camera Flaw Exploited by Hackers for Botnet Attacks

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.

By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Whatsapp Whatsapp LinkedIn Reddit Telegram Email Copy Link Print
Share
Previous Article Conditional Properties and Resources in CloudFormation Templates | by Teri Radichel | Cloud Security | Apr, 2023
Next Article ChatGPT’s Data Protection Blind Spots and How Security Teams Can Solve Them
Leave a comment Leave a comment

Comments (0) Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

235.3k Followers Like
69.1k Followers Follow
11.6k Followers Pin
56.4k Followers Follow
136k Subscribers Subscribe
4.4k Followers Follow
- Advertisement -
Ad imageAd image

Latest News

From Prompt Injection To Account Takeover · Embrace The Red
Pentesting 6 December 2025
From Prompt Injection To Account Takeover · Embrace The Red
Pentesting 6 December 2025
Ways to Tell if a Website Is Fake
network vulnerability 6 December 2025
From Prompt Injection To Account Takeover · Embrace The Red
Pentesting 6 December 2025
//

We influence 20 million users and is the number one business and technology news network on the planet

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

Loading
Sécurité Helvétique News | AmyrisSécurité Helvétique News | Amyris
Follow US
© 2023 Sécurité Helvétique NEWS par Amyris Sarl. Tous droits réservés
Amyris news letter
Join Us!

Subscribe to our newsletter and never miss our latest news, podcasts etc..

Loading
Zero spam, Unsubscribe at any time.
login Amyris SH
Welcome Back!

Sign in to your account

Lost your password?