Blockchain & AI
MALWARE OPERATORS TARGET CRYPTO TRADERS USING MAC APPS
Investigators at cybersecurity firm ESET have found GMERA malware targeting crypto traders using applications on Apple’s macOS.
According to Slovakia-based ESET, the malware has been integrated into sophisticated convincing-looking trading applications that provide full functionality but also steal users’ crypto funds.
Those behind the malware have integrated it into a fake copy of the popular cryptocurrency trading application Kattana, and have also produced slick copies of the company’s website – copies easily good enough to fool those new to Kattana.
Currently the crooks are also believed to be promoting four malware loaded copycat trading apps; Cointrazer, Cupatrade, Licatrade, and Trezarus. The fraudulent websites contain links to download ZIP archives which contain trojanised versions of the apps.
Stealing user names, crypto wallets and screen captures
ESET says it has tested samples from Licatrade, which though slightly different to the other apps, functions in much the same way, with the trojan installing a shell script in the victim’s machine, giving the hackers access to their system.
The crooks can then create command-and-control servers (C&C or C2), over HTTP between their own system and the victim’s. They can then steal information including user names, crypto wallets, location, and screen captures.
ESET reported their finding to Apple, which quickly revoked the certificate issues to Licatrade. Two certificates used by other malware loaded trading apps have also been revoked.
GMERA malware was first discovered by cybersecurity firm Trend Micro in September 2019 – in an app imitating Mac-specific stock investment app Stockfolio.
According to ESET, the email address that registered the licatrade.com domain was the same as that which registered repbaerray.pw and macstockfolio.com – both of which were associated with the GMERA-laden Stockfolio app clone.
Promoted by social engineering?
Interestingly, researchers say they still aren’t sure exactly how someone specifically becomes a victim of this hacking group in the first place, but suspect the dodgy operators directly contact their targets and “socially engineer” them into installing the malicious applications.
They also noted that the mitigation implementation in the most recent version of macOS, Catalina, has worked to limit the success of the hackers because it requires the user of the machine to give permission for a screen capture to be taken – thus alerting them to the fact the malware is installed.
AYO.NEWS says:
There are still a fair few annoyingly smug Mac users who believe the myth that they are safe from viruses and malware, so they should sit up and take note, especially if they are using their machines to trade crypto.
But anyone trading crypto, on any machine or operating system, should always follow a few simple rules; always double check you are on the legitimate site and not a clone, and be extremely careful interacting with anyone who approaches you on social media regarding crypto trading opportunities.
‘AYO.NEWS says’ features the opinion of the author and does not necessarily reflect the views of Pentagon Digital Limited or its affiliates or associates.
All original content featured on this site is © Pentagon Digital Limited, 2020