Apple users beware: New malware hijacks crypto via fake blockchain games

TL;DR Breakdown

  • “Realst”, a new infostealer malware, targets Apple macOS users through fake blockchain games.
  • The malware silently scrapes web browser data, including passwords, and can quickly drain cryptocurrency wallets.
  • Users can protect themselves by only installing apps from the official Mac App Store, verifying links, using strong passwords, enabling two-step authentication, and keeping devices and applications updated.

Description

Security researchers have identified a new infostealer malware named “Realst”, which is currently being used by cybercriminals to target Apple macOS users, including those on the upcoming macOS 14 Sonoma.  However, Web3 security firm SlowMist warned through a blog post that the malware is being propagated through fake blockchain games such as Brawl Earth, WildWorld, … Read more

Security researchers have identified a new infostealer malware named “Realst”, which is currently being used by cybercriminals to target Apple macOS users, including those on the upcoming macOS 14 Sonoma. 

However, Web3 security firm SlowMist warned through a blog post that the malware is being propagated through fake blockchain games such as Brawl Earth, WildWorld, Dawnland, Destruction, Evolion, Pearl, Olymp of Reptiles, and SaintLegend. Each game has its own website, Twitter, and Discord accounts, creating a false sense of legitimacy that has unfortunately led to some users becoming victims.

The malware is written in Rust, an emerging programming language. Some variants of the malware are already targeting macOS 14 Sonoma, which is set to be released in the fall. The malware’s code mentions Sonoma multiple times, indicating the intent of the author to remain active until the public release of Apple’s latest macOS version.

The modus operandi of Realst

Realst operates silently in the background of compromised macOS devices, scraping web browser data, including stored passwords, and sending it back to the threat actors. It targets popular web browsers such as Firefox, Chrome, Opera, Brave, and Vivaldi, but does not target Safari. One of the most alarming consequences of infection is that Realst can quickly empty cryptocurrency wallets within minutes.

The malware is distributed via malicious websites promoting fake blockchain games, according to web3 security firm SlowMist. The malware attempts to deceive victims through AppleScript spoofing — presenting password request dialog boxes with hidden answers to capture passwords. Sometimes, it also uses Chainbreaker, an open-source project to extract passwords, keys, and certificates from macOS keychain databases.

Protecting against Realst and other malware

To protect against Realst and other malware, users are advised to only install apps from the official Mac App Store, verify links before opening them, use strong passwords and enable two-step authentication, exercise caution when granting permissions on their Mac, and keep their devices and applications up-to-date. 

SentinelOne’s security solution can detect and prevent all known variants of Realst. However, users and security teams are urged to remain vigilant as Apple’s malware blocking service ‘XProtect’ does not appear to currently prevent execution of this malware.

Given the rising popularity of blockchain games promising financial rewards, users are advised to exercise extreme caution when encountering solicitations to download and run such games. 

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Apple users beware: New malware hijacks crypto via fake blockchain games

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年7月27日 19:01
Next 2023年7月27日 19:59

Related articles

  • Top crypto tweets of the day – August 9th

    Description Contents hide 1 Fantom’s DEX SpiritSwap is running low on funds and might close shop 2 Neuralink, Elon Musk’s brain implant startup, raises $280 million 3 Over the weekend, USDT again lost its dollar peg on centralized exchanges 4 Dogecoin ready for a breakout? 5 Total TVL declines 6 Threads vs. Twitter (X) 7 Cumulative … Read more Contents hide 1 Fantom’s DEX SpiritSwap is running low on funds and might close shop 2 Neuralink, Elon Musk’s brain implant startup, raises $280 million 3 Over the weekend, USDT again lost its dollar peg on centralized exchanges 4 Dogecoin ready for a breakout? 5 Total TVL declines 6 Threads vs. Twitter (X) 7 Cumulative Bitcoin transaction volume (change-adjusted) just went above $40 trillion 8 Crypto is now trading in a continuation bullish pattern 9 Many altcoins are showing signs of life 10 Paypal stablecoins PYUSD’s first transaction tested a value of $69.42069 11 BlackRock insiders say spot Bitcoin ETF approval is expected within six months 12 Ethereum just surpassed 100 Million non-zero addresses 13 X/Twitter fined $350,000 Fantom’s DEX SpiritSwap…

    Article 2023年8月10日
  • FCA digital assets head resigns less than a year after joining

    TL;DR Breakdown Binu Paul, the head of digital assets for the U.K.’s Financial Conduct Authority (FCA), resigns less than a year after joining Paul’s departure comes amid U.K.’s efforts to be the world’s web3 center and establishing clear regulation guidelines for digital assets. Description Binu Paul, the head of digital assets for the U.K.’s Financial Conduct Authority (FCA), has bid the organization goodbye less than a year after being appointed. Paul initially worked as a fintech specialist lead at the Financial Markets Authority in New Zealand. Last year in October, he was appointed to join the UK FCA, whereby … Read more Binu Paul, the head of digital assets for the U.K.’s Financial Conduct Authority (FCA), has bid the organization goodbye less than a year after being appointed. Paul initially worked as a fintech specialist lead at the Financial Markets Authority in New Zealand. Last year in October, he was appointed to join the UK FCA, whereby he took over from Victoria McLoughlin as the head of digital assets. As the head, he led the FCA regulatory activities in the…

    Article 2023年6月28日
  • SEC vs. Binance: $115 billion battle over crypto regulation

    TL;DR Breakdown SEC has expanded its list of cryptocurrencies classified as unregistered securities, adding around US$115 billion worth of tokens. The SEC has recently filed 13 charges against Binance, accusing the exchange of making unregistered and unlawful offers and sales of its BNB and BUSD tokens. Binance has reacted to the SEC’s allegations, claiming that its BNB token is not a security, but a native token designed to fuel an internal economy. In an unexpected turn of events this week, the U.S. Securities and Exchange Commission (SEC) has delivered a shockwave through the digital currency universe. According to reports, the regulatory body has swelled the list of cryptocurrencies it categorizes as unregistered securities, adding approximately $115 billion worth of tokens. The latest twist in cryptocurrency regulation has come about due to a lawsuit filed by the SEC against the crypto exchange Binance. In its most recent move, the SEC has ruffled feathers within the crypto community by declaring that several tokens traded on Binance, including Binance’s own BNB token, the stablecoin BUSD, and other cryptocurrencies such as Solana, Cardano’s (ADA),…

    Article 2023年6月11日
  • Hooked Protocol price analysis: HOOK soars in the direction of $1.48 as bullish momentum returns.

    TL;DR Breakdown Hooked Protocol price analysis shows a bullish trend Resistance for HOOK is present at $1.50 Support for HOOK/USD is present at $1.41 Hooked Protocol price analysis is on a bullish trend today, with the HOOK/USD pair rising to the $1.48 mark. The bulls have been pushing hard on the current support level of $1.41 as they attempt to break through the resistance at the $1.50 mark, which appears to be a key psychological level for traders. The price is currently trading at $1.48 after having gained more than 2.48% in the last 24 hours. The volume has also seen an increase, with over $28 million up over the last 24 hours. This indicates that traders are expecting a further rise in price. The bullish momentum is expected to continue as the coin is supported by strong buying pressure and a strong bullish trend line. Hooked Protocol price analysis 1-day chart: HOOK trades above $1.48, gaining over 2.48% The Hooked Protocol price analysis is on the bullish side today. Bulls have taken the price up to the $1.48 mark,…

    Article 2023年6月6日
  • Five Times Crypto Detective ZachXBT Opened Investors’ Eyes 

    Description Clear, reliable information is paramount in cryptocurrency’s dynamic and often opaque world. Enter ZachXBT, a renowned crypto detective who has made a name for himself by providing crucial insights and revealing hidden truths within the crypto market.  From unearthing fraudulent schemes to identifying promising opportunities, ZachXBT’s work has consistently shed light on the complex intricacies … Read more Clear, reliable information is paramount in cryptocurrency’s dynamic and often opaque world. Enter ZachXBT, a renowned crypto detective who has made a name for himself by providing crucial insights and revealing hidden truths within the crypto market.  From unearthing fraudulent schemes to identifying promising opportunities, ZachXBT’s work has consistently shed light on the complex intricacies of the crypto world. His analyses have helped investors make informed decisions and contributed to the overall transparency and integrity of the crypto market. This piece will thoroughly explore these five instances, providing an in-depth look at how ZachXBT’s detective work has impacted the crypto investment landscape. Whether you’re a seasoned investor or a newcomer to crypto, these stories offer valuable lessons and insights into cryptocurrency…

    Article 2023年7月25日
TOP