Apple users beware: New malware hijacks crypto via fake blockchain games

TL;DR Breakdown

  • “Realst”, a new infostealer malware, targets Apple macOS users through fake blockchain games.
  • The malware silently scrapes web browser data, including passwords, and can quickly drain cryptocurrency wallets.
  • Users can protect themselves by only installing apps from the official Mac App Store, verifying links, using strong passwords, enabling two-step authentication, and keeping devices and applications updated.

Description

Security researchers have identified a new infostealer malware named “Realst”, which is currently being used by cybercriminals to target Apple macOS users, including those on the upcoming macOS 14 Sonoma.  However, Web3 security firm SlowMist warned through a blog post that the malware is being propagated through fake blockchain games such as Brawl Earth, WildWorld, … Read more

Security researchers have identified a new infostealer malware named “Realst”, which is currently being used by cybercriminals to target Apple macOS users, including those on the upcoming macOS 14 Sonoma. 

However, Web3 security firm SlowMist warned through a blog post that the malware is being propagated through fake blockchain games such as Brawl Earth, WildWorld, Dawnland, Destruction, Evolion, Pearl, Olymp of Reptiles, and SaintLegend. Each game has its own website, Twitter, and Discord accounts, creating a false sense of legitimacy that has unfortunately led to some users becoming victims.

The malware is written in Rust, an emerging programming language. Some variants of the malware are already targeting macOS 14 Sonoma, which is set to be released in the fall. The malware’s code mentions Sonoma multiple times, indicating the intent of the author to remain active until the public release of Apple’s latest macOS version.

The modus operandi of Realst

Realst operates silently in the background of compromised macOS devices, scraping web browser data, including stored passwords, and sending it back to the threat actors. It targets popular web browsers such as Firefox, Chrome, Opera, Brave, and Vivaldi, but does not target Safari. One of the most alarming consequences of infection is that Realst can quickly empty cryptocurrency wallets within minutes.

The malware is distributed via malicious websites promoting fake blockchain games, according to web3 security firm SlowMist. The malware attempts to deceive victims through AppleScript spoofing — presenting password request dialog boxes with hidden answers to capture passwords. Sometimes, it also uses Chainbreaker, an open-source project to extract passwords, keys, and certificates from macOS keychain databases.

Protecting against Realst and other malware

To protect against Realst and other malware, users are advised to only install apps from the official Mac App Store, verify links before opening them, use strong passwords and enable two-step authentication, exercise caution when granting permissions on their Mac, and keep their devices and applications up-to-date. 

SentinelOne’s security solution can detect and prevent all known variants of Realst. However, users and security teams are urged to remain vigilant as Apple’s malware blocking service ‘XProtect’ does not appear to currently prevent execution of this malware.

Given the rising popularity of blockchain games promising financial rewards, users are advised to exercise extreme caution when encountering solicitations to download and run such games. 

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Apple users beware: New malware hijacks crypto via fake blockchain games

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年7月27日 19:01
Next 2023年7月27日 19:59

Related articles

  • Multichain loses another $103 million in a potential rugpull

    TL;DR Breakdown Multichain has suffered another $103 million hack in a potential inside job. Implications of the action on Defi and trust in the crypto space. Description In what is being considered one of the largest cryptocurrency hacks to date, cross-chain bridge Multichain fell victim to a devastating breach resulting in the loss of $125 million. Recent reports from blockchain data firm Chainalysis suggest that the exploit may have been an inside job, leaving the cryptocurrency community stunned and searching for answers. … Read more In what is being considered one of the largest cryptocurrency hacks to date, cross-chain bridge Multichain fell victim to a devastating breach resulting in the loss of $125 million. Recent reports from blockchain data firm Chainalysis suggest that the exploit may have been an inside job, leaving the cryptocurrency community stunned and searching for answers. In a new twist, the firm has lost another $103 million which were transferred in bits to different addresses. Multichain has now lost $228 million to exploits Multichain, formerly known as Anyswap, operates as a cross-chain protocol that enables the…

    Article 2023年7月12日
  • Liquity price analysis: LQTY price falls to $1.26 as bears reclaim control

    TL;DR Breakdown Liquity price analysis is bearish today LQTY resistance level is at $1.727 LQTY/USD support is at $1.012 Liquity price analysis is bearish today as the market is in a downward trend. The price has been decreasing over the past 24 hours, and it looks like this trend will continue in the near future. The bears are in control of the market, and it’s likely that we will see further declines as the day progresses. The price is currently below the $1.26 level, with a decrease of 3.79% at the time of writing. It is important to note that while LQTY prices may be bearish right now, there is still potential for a rebound in the near future. Traders should watch closely for any signs of upside momentum before entering into any positions. Liquity price analysis 1-day chart: LQTY price dips to $1.26 showing a negative sign  The 1-day Liquity price analysis shows a downward trend and bearish sentiment in the market. The bulls have been unable to break through the $1.727 resistance level, leading to a decrease in…

    Article 2023年5月23日
  • Ukraine joins G7 in its fight against Russia and China

    TL;DR Breakdown In a significant geopolitical development, Ukraine’s President, Volodymyr Zelenskiy, has joined forces with the G7 nations in their stand against Russia and China. Zelenskiy held critical talks with India’s Prime Minister Narendra Modi at the G7 summit in Hiroshima, discussing Ukraine’s requirements and inviting India to participate in Ukraine’s peace initiatives. Despite India’s economic ties with Russia, PM Modi pledged continued humanitarian support for Ukraine and expressed his backing for diplomatic solutions and peace. In an unprecedented move, Ukraine has partnered with the Group of Seven (G7) in its stand against Russia and China, marking a significant geopolitical shift. Spearheading this effort, Ukraine’s President Volodymyr Zelenskiy took center stage in Hiroshima, Japan, at the G7 summit this past weekend, intensifying efforts to rally international support against the ongoing conflict with Russia. Ukraine strengthens global ties During the three-day G7 summit, Zelenskiy held crucial discussions with India’s Prime Minister, Narendra Modi, and other leaders from non-aligned nations. These discussions, coupled with the backing of the G7 nations, serve to amplify Ukraine’s message on a global scale. Donning his signature…

    Article 2023年5月21日
  • Crypto Founder Charles Hoskinson Explains Decision to Keep No Public Crypto Addresses

    TL;DR Breakdown Charles Hoskinson, Cardano’s founder, does not have public crypto addresses to protect against potential risks from unauthorized transfers and regulatory challenges. He prefers contingent settlement as an alternative approach, raising speculations about innovative applications within the Cardano blockchain or other projects. Description In a departure from the norm among prominent figures in the cryptocurrency space, Cardano founder Charles Hoskinson has revealed that he maintains no public crypto addresses. This surprising revelation has drawn attention and raised questions from the community. Hoskinson took to Twitter to provide a detailed explanation for his decision, citing security concerns as the … Read more In a departure from the norm among prominent figures in the cryptocurrency space, Cardano founder Charles Hoskinson has revealed that he maintains no public crypto addresses. This surprising revelation has drawn attention and raised questions from the community. Hoskinson took to Twitter to provide a detailed explanation for his decision, citing security concerns as the primary motivation behind keeping his addresses private. Contents hide 1 Security Concerns Drive Hoskinson’s Decision 2 Contingent Settlement as an Alternative 3 Benefits…

    Article 2023年7月31日
  • BlackRock’s spot Bitcoin ETF filing sparks optimism

    TL;DR Breakdown BlackRock’s filing pushes other firms to file their applications. Fidelity investments could make a last-minute entry into the market. Description The race for spot Bitcoin exchange-traded funds (ETFs) has intensified as two investment firms recently filed applications, following BlackRock’s move to seek approval for its spot Bitcoin ETF on June 15. BlackRock leads other firms in filing their spot Bitcoin ETF application WisdomTree, an asset management fund based in New York, is the latest firm … Read more The race for spot Bitcoin exchange-traded funds (ETFs) has intensified as two investment firms recently filed applications, following BlackRock’s move to seek approval for its spot Bitcoin ETF on June 15. BlackRock leads other firms in filing their spot Bitcoin ETF application WisdomTree, an asset management fund based in New York, is the latest firm to file a new application for a spot Bitcoin ETF. In a filing to the United States Securities and Exchange Commission (SEC) on June 21, WisdomTree requested permission to list its “WisdomTree Bitcoin Trust” on the Cboe BZX Exchange under the ticker symbol “BTCW.” This…

    Article 2023年6月24日
TOP