Apple users beware: New malware hijacks crypto via fake blockchain games

TL;DR Breakdown

  • “Realst”, a new infostealer malware, targets Apple macOS users through fake blockchain games.
  • The malware silently scrapes web browser data, including passwords, and can quickly drain cryptocurrency wallets.
  • Users can protect themselves by only installing apps from the official Mac App Store, verifying links, using strong passwords, enabling two-step authentication, and keeping devices and applications updated.

Description

Security researchers have identified a new infostealer malware named “Realst”, which is currently being used by cybercriminals to target Apple macOS users, including those on the upcoming macOS 14 Sonoma.  However, Web3 security firm SlowMist warned through a blog post that the malware is being propagated through fake blockchain games such as Brawl Earth, WildWorld, … Read more

Security researchers have identified a new infostealer malware named “Realst”, which is currently being used by cybercriminals to target Apple macOS users, including those on the upcoming macOS 14 Sonoma. 

However, Web3 security firm SlowMist warned through a blog post that the malware is being propagated through fake blockchain games such as Brawl Earth, WildWorld, Dawnland, Destruction, Evolion, Pearl, Olymp of Reptiles, and SaintLegend. Each game has its own website, Twitter, and Discord accounts, creating a false sense of legitimacy that has unfortunately led to some users becoming victims.

The malware is written in Rust, an emerging programming language. Some variants of the malware are already targeting macOS 14 Sonoma, which is set to be released in the fall. The malware’s code mentions Sonoma multiple times, indicating the intent of the author to remain active until the public release of Apple’s latest macOS version.

The modus operandi of Realst

Realst operates silently in the background of compromised macOS devices, scraping web browser data, including stored passwords, and sending it back to the threat actors. It targets popular web browsers such as Firefox, Chrome, Opera, Brave, and Vivaldi, but does not target Safari. One of the most alarming consequences of infection is that Realst can quickly empty cryptocurrency wallets within minutes.

The malware is distributed via malicious websites promoting fake blockchain games, according to web3 security firm SlowMist. The malware attempts to deceive victims through AppleScript spoofing — presenting password request dialog boxes with hidden answers to capture passwords. Sometimes, it also uses Chainbreaker, an open-source project to extract passwords, keys, and certificates from macOS keychain databases.

Protecting against Realst and other malware

To protect against Realst and other malware, users are advised to only install apps from the official Mac App Store, verify links before opening them, use strong passwords and enable two-step authentication, exercise caution when granting permissions on their Mac, and keep their devices and applications up-to-date. 

SentinelOne’s security solution can detect and prevent all known variants of Realst. However, users and security teams are urged to remain vigilant as Apple’s malware blocking service ‘XProtect’ does not appear to currently prevent execution of this malware.

Given the rising popularity of blockchain games promising financial rewards, users are advised to exercise extreme caution when encountering solicitations to download and run such games. 

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Apple users beware: New malware hijacks crypto via fake blockchain games

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年7月27日 19:01
Next 2023年7月27日 19:59

Related articles

  • Grayscale Investments ramps up DeFi interest  with Lido addition

    TL;DR Breakdown rayscale Investments, the world’s leading digital asset manager, has expanded its DeFi Fund by including Lido (LDO), marking a significant development in the liquid staking space. Liquid staking allows investors to earn staking rewards without locking up their tokens, providing increased liquidity and flexibility. This trend is gaining popularity as it caters to growing demand in the DeFi sector. The addition of LDO to Grayscale’s DeFi Fund signals rising institutional interest in liquid staking services and could potentially influence wider adoption and evolution in this space, despite the current performance of the DeFi Fund. Description In a significant move, Grayscale Investments, the world’s largest digital asset manager, has expanded its Decentralized Finance (DeFi) Fund with the inclusion of Lido (LDO). The addition bolsters the prominence of liquid staking services, spotlighting a potentially transformative trend in the broader crypto ecosystem. Liquid staking: The next big wave in DeFi Lido, a pioneer … Read more In a significant move, Grayscale Investments, the world’s largest digital asset manager, has expanded its Decentralized Finance (DeFi) Fund with the inclusion of Lido (LDO)….

    Article 2023年7月9日
  • Voyager App to Resume Customer Withdrawals, Initiating Recovery Process

    TL;DR Breakdown Voyager app set to reopen: Customers will soon be able to withdraw their funds from the Voyager app after the company’s Chapter 11 bankruptcy filing nearly one year ago. Initial distribution and outstanding debts: Customers will initially receive 35.72% of their claims through cryptocurrency or cash withdrawals. After a lengthy period of uncertainty, cryptocurrency brokerage Voyager Digital is set to reopen its app, granting customers the long-awaited ability to withdraw their funds. Almost a year after filing for Chapter 11 bankruptcy, the company has made significant strides toward financial recovery. With the Voyager app’s imminent update, customers will finally have visibility into the available withdrawal amounts, offering a glimmer of hope and restoring confidence in the platform. Contents hide 1 Voyager App Updated to Display Withdrawal Amounts 2 Initial Distribution Provides 35.72% of Claims 3 Pending Resolution May Unlock Additional Funds for Creditors 4 Conclusion Voyager App Updated to Display Withdrawal Amounts Voyager Digital, a prominent cryptocurrency brokerage, is preparing to reopen its app, allowing customers to finally withdraw their funds after nearly one year since filing for…

    Article 2023年6月18日
  • Friend.Tech is no more – Activity tanks by 94%

    TL;DR Breakdown The daily trading volume on Friend.Tech has decreased by 94% from its all-time high, while the number of daily traders has fallen by 83%.  Friend.Tech network fees dropped from $1.7 million on August 21 to $95,000 on August 27. The collapse of Friend.Tech has left a bitter taste performance on Coinbase’s Base Network. Description The latest craze in the crypto world, Friend.Tech, is facing a significant issue with the presence of automated bots and speculative games. These bots are capable of manipulating the platform, affecting its integrity and fairness. Automated bot activity can manipulate trading volumes, prices, and other market-related metrics. Blink, and you will most probably miss the … Read more The latest craze in the crypto world, Friend.Tech, is facing a significant issue with the presence of automated bots and speculative games. These bots are capable of manipulating the platform, affecting its integrity and fairness. Automated bot activity can manipulate trading volumes, prices, and other market-related metrics. Blink, and you will most probably miss the latest crypto fad. Critics have quickly labeled the decentralized social network…

    Article 2023年8月28日
  • Coinbase director recovers $322,000 in crypto for stranger

    TL;DR Breakdown Coinbase director Conor Grogan uncovers $322,000 worth of dormant crypto for a stranger Grogan found 20 addresses with over $250,000 worth of crypto in the wallets that were untouched for years Description Coinbase director Conor Grogan, in a recent Twitter poster, has explained how he uncovered $322,000 worth of dormant crypto for a stranger. During the Ethereum fork of 2016, it led to the Ethereum Classic(ETC) creation. All investors that held ether on-chain received an identical ETC amount. According to Grogan, most people have yet to touch … Read more Coinbase director Conor Grogan, in a recent Twitter poster, has explained how he uncovered $322,000 worth of dormant crypto for a stranger. During the Ethereum fork of 2016, it led to the Ethereum Classic(ETC) creation. All investors that held ether on-chain received an identical ETC amount. According to Grogan, most people have yet to touch these funds and as a result, has recovered funds in six-figure amounts for investors in the past. In a screenshot after that, he shared that he previously notified a Twitter user of 23…

    Article 2023年7月7日
  • BRICS has a China problem, and it is a bit concerning

    TL;DR Breakdown The BRICS alliance is facing an imbalance with China’s economic dominance overshadowing other members. China’s assertive stance in foreign and military affairs due to its economic might poses issues for the consortium. Strained relationships with India and Russia and rivalries with the U.S. are raising concerns. Description A keen observer of global diplomacy might have noticed an unusual absence at an upcoming international summit. This is not the first time that the BRICS assembly has seen such a situation, with Russia’s President, Vladimir Putin, choosing to bypass the meeting out of fear that the host country, South Africa, might act upon an … Read more A keen observer of global diplomacy might have noticed an unusual absence at an upcoming international summit. This is not the first time that the BRICS assembly has seen such a situation, with Russia’s President, Vladimir Putin, choosing to bypass the meeting out of fear that the host country, South Africa, might act upon an international arrest warrant against him. The implications of this hiccup might not run deep, but they highlight a…

    Article 2023年7月28日
TOP