Apple users beware: New malware hijacks crypto via fake blockchain games

TL;DR Breakdown

  • “Realst”, a new infostealer malware, targets Apple macOS users through fake blockchain games.
  • The malware silently scrapes web browser data, including passwords, and can quickly drain cryptocurrency wallets.
  • Users can protect themselves by only installing apps from the official Mac App Store, verifying links, using strong passwords, enabling two-step authentication, and keeping devices and applications updated.

Description

Security researchers have identified a new infostealer malware named “Realst”, which is currently being used by cybercriminals to target Apple macOS users, including those on the upcoming macOS 14 Sonoma.  However, Web3 security firm SlowMist warned through a blog post that the malware is being propagated through fake blockchain games such as Brawl Earth, WildWorld, … Read more

Security researchers have identified a new infostealer malware named “Realst”, which is currently being used by cybercriminals to target Apple macOS users, including those on the upcoming macOS 14 Sonoma. 

However, Web3 security firm SlowMist warned through a blog post that the malware is being propagated through fake blockchain games such as Brawl Earth, WildWorld, Dawnland, Destruction, Evolion, Pearl, Olymp of Reptiles, and SaintLegend. Each game has its own website, Twitter, and Discord accounts, creating a false sense of legitimacy that has unfortunately led to some users becoming victims.

The malware is written in Rust, an emerging programming language. Some variants of the malware are already targeting macOS 14 Sonoma, which is set to be released in the fall. The malware’s code mentions Sonoma multiple times, indicating the intent of the author to remain active until the public release of Apple’s latest macOS version.

The modus operandi of Realst

Realst operates silently in the background of compromised macOS devices, scraping web browser data, including stored passwords, and sending it back to the threat actors. It targets popular web browsers such as Firefox, Chrome, Opera, Brave, and Vivaldi, but does not target Safari. One of the most alarming consequences of infection is that Realst can quickly empty cryptocurrency wallets within minutes.

The malware is distributed via malicious websites promoting fake blockchain games, according to web3 security firm SlowMist. The malware attempts to deceive victims through AppleScript spoofing — presenting password request dialog boxes with hidden answers to capture passwords. Sometimes, it also uses Chainbreaker, an open-source project to extract passwords, keys, and certificates from macOS keychain databases.

Protecting against Realst and other malware

To protect against Realst and other malware, users are advised to only install apps from the official Mac App Store, verify links before opening them, use strong passwords and enable two-step authentication, exercise caution when granting permissions on their Mac, and keep their devices and applications up-to-date. 

SentinelOne’s security solution can detect and prevent all known variants of Realst. However, users and security teams are urged to remain vigilant as Apple’s malware blocking service ‘XProtect’ does not appear to currently prevent execution of this malware.

Given the rising popularity of blockchain games promising financial rewards, users are advised to exercise extreme caution when encountering solicitations to download and run such games. 

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Apple users beware: New malware hijacks crypto via fake blockchain games

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年7月27日 19:01
Next 2023年7月27日 19:59

Related articles

  • Former Mt. Gox CEO recalls his time behind bars as FTX CEO’s plea for release denied

    TL;DR Breakdown Mark Karpelès, the former CEO of the now-defunct cryptocurrency exchange Mt. Gox, has shared his perspective on the recent SBF plea. After more than four years of legal battles, Karpelès attributed his successful defense to the “little calculator” and the diligent work of his legal team.  During his incarceration, Karpelès had limited access to technology and computing resources.  Description Mark Karpelès, the former CEO of the now-defunct cryptocurrency exchange Mt. Gox, has shared his perspective on the recent plea by former FTX CEO Sam Bankman-Fried for release from prison due to poor internet access. Karpelès, who faced his own legal battles in the past, expressed little sympathy for Bankman-Fried’s situation. In a September 13 … Read more Mark Karpelès, the former CEO of the now-defunct cryptocurrency exchange Mt. Gox, has shared his perspective on the recent plea by former FTX CEO Sam Bankman-Fried for release from prison due to poor internet access. Karpelès, who faced his own legal battles in the past, expressed little sympathy for Bankman-Fried’s situation. In a September 13 post on social media platform X…

    Article 2023年9月14日
  • Shake-Up at Sequoia Capital: Departures of Key Partners Mark Transformation

    TL;DR Breakdown Michael Moritz, a long-time partner at Sequoia Capital, is leaving to shift his focus to Sequoia Heritage, a wealth management enterprise he co-founded. Sequoia Capital faces reputational damage due to its involvement in the collapse of FTX, a cryptocurrency exchange, resulting in the loss of millions from its global growth fund. Description Sequoia Capital, the renowned venture capital firm with a storied history of successful investments, has experienced a series of significant transformations in the past year. This period has been marked by market turbulence, restructuring, and the departure of several key investors. Among those leaving the firm is veteran partner Michael Moritz, who will shift his … Read more Sequoia Capital, the renowned venture capital firm with a storied history of successful investments, has experienced a series of significant transformations in the past year. This period has been marked by market turbulence, restructuring, and the departure of several key investors. Among those leaving the firm is veteran partner Michael Moritz, who will shift his focus to Sequoia Heritage, a wealth management enterprise he co-founded. These departures come…

    Article 2023年7月20日
  • Best Twitter threads of the day – August 30th

    Description Top crypto price predictions for the 2024–2025 bull run Elon Musk’s SECRET Master Plan for X Top crypto price predictions for the 2024–2025 bull run Grayscale made the whole market green! Analysts are calling for imminent #Bitcoin ETF approval. This will cause over $𝟭𝟬𝗧 of new money to flow into Bitcoin and #Crypto A thread on top crypto price predictions for the 2024–2025 bull run 🧵 (Like & Retweet) pic.twitter.com/ld7Ql5Druv — Sjuul | AltCryptoGems (@AltCryptoGems) August 30, 2023 Before we start, I want you to bookmark this thread for the CT culture so that you can come back in the future and see how these predictions went. In the last bull run, the total crypto market cap topped at $3T and I expect this number to go at least 3x by the next bull run. — Sjuul | AltCryptoGems (@AltCryptoGems) August 30, 2023 In this thread, I have assumed a few things. – Bitcoin will still be no. 1 with around 35%–40% dominance at the peak, and ETH will still be the no.2 – Legacy coins and meme coins…

    Article 2023年8月31日
  • Xi Jinping’s playbook decoded for China observers

    Description Navigating the enigmatic twists and turns of China’s political and economic strategies feels like unraveling a Gordian knot. There’s a whirlwind of speculations about whether the decisions and trajectory are orchestrated by its current leader, Xi Jinping, or have roots in the foundational principles of the Chinese Communist Party (CCP) dating back to 1949. China, … Read more Navigating the enigmatic twists and turns of China’s political and economic strategies feels like unraveling a Gordian knot. There’s a whirlwind of speculations about whether the decisions and trajectory are orchestrated by its current leader, Xi Jinping, or have roots in the foundational principles of the Chinese Communist Party (CCP) dating back to 1949. China, with its colossal economic ambitions, seems to be maneuvering in a direction that perplexingly undercuts its potential. Shifting Gears or Hitting the Brakes? The list of China’s recent economic decisions reads like a baffling script. Think about prominent entrepreneurs vanishing off the public radar, stringent espionage laws that tangle up business operations, or the stark pivot from nurturing the private sector to favoring state-owned enterprises. These…

    Article 2023年9月21日
  • Gary Gensler doubles down on crypto chockpoint 2.0

    TL;DR Breakdown Despite recent setbacks in court for the SEC, chief Gary Gensler is still sticking to his crypto industry criticism. As per a written testimony set to be delivered to the Senate Banking Committee on Tuesday, Gary Gensler is holding the line on warning about the sector flouting securities laws. A number of crypto companies facing lawsuits from the SEC are likely to use Ripple’s win in their own motions to dismiss cases. Description In a move signaling neither retreat nor compromise, SEC Chairman Gary Gensler is doubling down on his criticisms of the crypto industry ahead of his much-anticipated Senate testimony. Known for his defiant stance against what he perceives as regulatory loopholes and grey areas in the rapidly evolving crypto landscape. Gary Gensler is expected to worsen … Read more In a move signaling neither retreat nor compromise, SEC Chairman Gary Gensler is doubling down on his criticisms of the crypto industry ahead of his much-anticipated Senate testimony. Known for his defiant stance against what he perceives as regulatory loopholes and grey areas in the rapidly evolving…

    Article 2023年9月12日
TOP