Apple users beware: New malware hijacks crypto via fake blockchain games

TL;DR Breakdown

  • “Realst”, a new infostealer malware, targets Apple macOS users through fake blockchain games.
  • The malware silently scrapes web browser data, including passwords, and can quickly drain cryptocurrency wallets.
  • Users can protect themselves by only installing apps from the official Mac App Store, verifying links, using strong passwords, enabling two-step authentication, and keeping devices and applications updated.

Description

Security researchers have identified a new infostealer malware named “Realst”, which is currently being used by cybercriminals to target Apple macOS users, including those on the upcoming macOS 14 Sonoma.  However, Web3 security firm SlowMist warned through a blog post that the malware is being propagated through fake blockchain games such as Brawl Earth, WildWorld, … Read more

Security researchers have identified a new infostealer malware named “Realst”, which is currently being used by cybercriminals to target Apple macOS users, including those on the upcoming macOS 14 Sonoma. 

However, Web3 security firm SlowMist warned through a blog post that the malware is being propagated through fake blockchain games such as Brawl Earth, WildWorld, Dawnland, Destruction, Evolion, Pearl, Olymp of Reptiles, and SaintLegend. Each game has its own website, Twitter, and Discord accounts, creating a false sense of legitimacy that has unfortunately led to some users becoming victims.

The malware is written in Rust, an emerging programming language. Some variants of the malware are already targeting macOS 14 Sonoma, which is set to be released in the fall. The malware’s code mentions Sonoma multiple times, indicating the intent of the author to remain active until the public release of Apple’s latest macOS version.

The modus operandi of Realst

Realst operates silently in the background of compromised macOS devices, scraping web browser data, including stored passwords, and sending it back to the threat actors. It targets popular web browsers such as Firefox, Chrome, Opera, Brave, and Vivaldi, but does not target Safari. One of the most alarming consequences of infection is that Realst can quickly empty cryptocurrency wallets within minutes.

The malware is distributed via malicious websites promoting fake blockchain games, according to web3 security firm SlowMist. The malware attempts to deceive victims through AppleScript spoofing — presenting password request dialog boxes with hidden answers to capture passwords. Sometimes, it also uses Chainbreaker, an open-source project to extract passwords, keys, and certificates from macOS keychain databases.

Protecting against Realst and other malware

To protect against Realst and other malware, users are advised to only install apps from the official Mac App Store, verify links before opening them, use strong passwords and enable two-step authentication, exercise caution when granting permissions on their Mac, and keep their devices and applications up-to-date. 

SentinelOne’s security solution can detect and prevent all known variants of Realst. However, users and security teams are urged to remain vigilant as Apple’s malware blocking service ‘XProtect’ does not appear to currently prevent execution of this malware.

Given the rising popularity of blockchain games promising financial rewards, users are advised to exercise extreme caution when encountering solicitations to download and run such games. 

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Apple users beware: New malware hijacks crypto via fake blockchain games

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年7月27日 19:01
Next 2023年7月27日 19:59

Related articles

  • Deutsche Bank’s former star pleads guilt to crypto fraud

    TL;DR Breakdown Rashawn Russell, previously associated with Deutsche Bank, pleaded guilty to a crypto fraud scheme in Brooklyn, NY. Russell’s R3 Crypto Fund promised high returns but misappropriated funds for personal use, defrauding 29 investors of over $1.5 million. Apart from the crypto scheme, Russell engaged in identity theft, fraudulently obtaining credit cards in third-party names. Description The world of cryptocurrencies is once again rocked by scandal. This time, the shockwaves are coming from Brooklyn, NY, where a previously shining star of the financial world has found himself ensnared in the dark web of deceit and crime. Rashawn Russell, once revered as a formidable figure in Deutsche Bank, now finds himself pleading … Read more The world of cryptocurrencies is once again rocked by scandal. This time, the shockwaves are coming from Brooklyn, NY, where a previously shining star of the financial world has found himself ensnared in the dark web of deceit and crime. Rashawn Russell, once revered as a formidable figure in Deutsche Bank, now finds himself pleading guilty to an elaborate crypto fraud scheme. From Banking Luminary…

    Article 2023年9月21日
  • Elon Musk initiates Twitter’s rebranding with an ‘X’ Symbol; X-branded tokens emerge

    TL;DR Breakdown Elon Musk replaces Twitter’s blue bird logo with a stylized ‘X’ as part of his vision to transform the platform into an “everything app.” The ‘X’ logo becomes Twitter’s new brand identity, projected on offices and embraced by CEO Linda Yaccarino, representing an AI-powered global marketplace for ideas and services. Concurrently, ‘X’ tokens appear on decentralized exchanges following Musk’s announcement, sparking interest and volatility in the cryptocurrency market. Description Billionaire entrepreneur Elon Musk has transformed Twitter’s iconic blue bird logo into a stylized X to metamorphose the 17-year-old social media platform into an all-encompassing application. However, the decision came shortly after Musk invited his vast following of 149 million users to suggest an X logo, which he promptly integrated into the platform’s branding. Over … Read more Billionaire entrepreneur Elon Musk has transformed Twitter’s iconic blue bird logo into a stylized X to metamorphose the 17-year-old social media platform into an all-encompassing application. However, the decision came shortly after Musk invited his vast following of 149 million users to suggest an X logo, which he promptly integrated into…

    Article 2023年7月24日
  • India, Russia discuss BRICS, G20, SCO cooperation in meeting

    TL;DR Breakdown Indian External Affairs Minister, Dr. S. Jaishankar, and Russian Foreign Minister, Sergey Lavrov, held a meeting to discuss cooperation within the BRICS, the G20, and the Shanghai Cooperation Organization (SCO). Both India and Russia are pushing for trade settlements in their national currencies, lessening their dependence on the U.S. dollar. These discussions were held during a two-day BRICS Foreign Ministers’ Meeting in Cape Town, South Africa. In the international diplomatic arena, an intriguing development has recently surfaced: two major global powers, India and Russia, are engaging in strategic dialogues focusing on strengthening cooperation within significant international forums, namely the BRICS, the Group of Twenty (G20), and the Shanghai Cooperation Organization (SCO). These discussions take on added significance as both countries are displaying a marked shift towards trade settlements in their respective national currencies, thereby diminishing their dependency on the U.S. dollar. A high-level diplomatic dialogue Dr. S. Jaishankar, India’s External Affairs Minister, recently met with his international counterparts, including Russia’s Foreign Minister Sergey Lavrov, during a two-day BRICS Foreign Ministers’ Meeting held in Cape Town, South Africa. The…

    Article 2023年6月6日
  • Bitbuy partners with Localcoin ATM to push crypto adoption in Canada

    TL;DR Breakdown Bitbuy has announced a strategic partnership with Localcoin ATM to push crypto adoption in Canada. Localcoin eyes the expansion as the road to further crypto adoption. Description Canadian fintech corporation WonderFi, with backing from billionaire Kevin O’Leary, has unveiled a strategic partnership between Bitbuy and cryptocurrency ATM provider Localcoin ATM. This significant collaboration, announced on September 18, aims to strengthen Localcoin’s cryptocurrency ATM network across Canada by integrating Bitbuy’s exchange platform, known for its deep liquidity. Bitbuy will leverage Localcoin’s ATM to … Read more Canadian fintech corporation WonderFi, with backing from billionaire Kevin O’Leary, has unveiled a strategic partnership between Bitbuy and cryptocurrency ATM provider Localcoin ATM. This significant collaboration, announced on September 18, aims to strengthen Localcoin’s cryptocurrency ATM network across Canada by integrating Bitbuy’s exchange platform, known for its deep liquidity. Bitbuy will leverage Localcoin’s ATM to provide its services Bitbuy holds the distinction of being the first cryptocurrency exchange in Canada to secure full regulatory approval, making it a key player in the country’s crypto landscape. In January 2023, WonderFi acquired Bitbuy’s parent company,…

    Article 2023年9月20日
  • Ramp Expands On-Ramp Service, Enabling Crypto Transactions with 40 New Fiat Currencies

    TL;DR Breakdown Ramp expands its platform compatibility, supporting 40 new fiat currencies, including the Bermudian dollar, Costa Rican colón, Hungarian forint, Mexican peso, Singapore dollar, and Swiss franc. The expansion empowers users in 150 countries to seamlessly transact between digital currencies and traditional currencies, promoting global crypto adoption and accessibility. Description Ramp, a leading financial technology company specializing in crypto infrastructure, has recently announced a significant expansion of its platform’s compatibility by adding support for 40 new fiat currencies. This move aims to simplify cross-border transactions and enable users to seamlessly transact with both digital and traditional currencies while benefiting from favorable conversion rates. The expansion … Read more Ramp, a leading financial technology company specializing in crypto infrastructure, has recently announced a significant expansion of its platform’s compatibility by adding support for 40 new fiat currencies. This move aims to simplify cross-border transactions and enable users to seamlessly transact with both digital and traditional currencies while benefiting from favorable conversion rates. The expansion is set to empower individuals across 150 countries, facilitating the conversion between cryptocurrencies and 43 fiat…

    Article 2023年6月24日
TOP