CoinThief Malware for Mac is hosted on popular websites and steals Bitcoins

bitcoin_keyAnother recently discovered variant of Mac Trojan "OSX / CoinThief" was found to be hosted on two popular websites, Download.com and MacUpdate.com.

CoinThief malware is designed to steal the login credentials that exchange Bitcoins from the victim, as well as the user name and the UUID (unique identifier) ​​of the Mac. It also collects information about Bitcoins-managed applications installed on the infected system.

See more articles from iGuRu.gr when you search for news on Google.

A few days ago, SecureMac spotted this Trojan, which had been uploaded under the name “ Stealthbit ” on GitHub and had been downloaded by hundreds of users. A Reddit user pointed out the similarity between the fake bitcoin app “ BitVanity ” and stealthbit.

SecureMac experts have also spotted yet another variant called “Bitcoin Ticker TTM” and “Litecoin Ticker” on popular download websites. The names of the apps appear to be copied from legitimate apps available on the Mac App Store.

This version installs a fake extension on Chrome, Safari, and Firefox browsers called Pop-up Blocker . The malicious extension records traffic to steal login credentials for bitcoin exchange websites. Once it has obtained the data, it communicates and sends it to a remote server.


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).