FacebookTwitterLinkedInTelegramCopy LinkEmail
Crime and Investigations

New macOS Malware Campaign Targets Crypto Wallet Users

New macOS Malware Campaign Targets Crypto Wallet Users

A new macOS malware campaign is targeting cryptocurrency users by harvesting browser credentials and wallet data, marking a shift in attacker tactics toward credential theft.

Summary:

  • The malware harvests sensitive data from macOS devices, including browser credentials and wallet-related files.
  • Researchers linked the campaign to phishing pages disguised as community onboarding websites.
  • Similar macOS information stealers have emerged in recent days, pointing to a broader threat trend.
  • Security experts recommend treating an infected device as fully compromised.

According to SlowMist, the latest campaign relies on social engineering rather than software vulnerabilities, reflecting a broader shift in cybercrime toward compromising users instead of blockchain networks.

The attackers reportedly create fake community application websites, including pages impersonating projects such as BuilDAO and Builder, using Google Sites to increase credibility. Victims are presented with fabricated system or OAuth-related errors and persuaded to download what appears to be a required application or security update.

Once installed, the malware quietly collects sensitive information stored across the operating system. Researchers said the malware extracts credentials from the macOS Keychain, browser databases used by applications such as Chrome, Brave and Arc, Apple Notes, and Telegram Desktop session files, giving attackers access to both financial and personal accounts.

The findings illustrate a growing preference among threat actors for stealing authentication data that can unlock cryptocurrency wallets, cloud services and communication platforms rather than attempting direct attacks on blockchain infrastructure.

Crypto Wallets Become a Primary Target

SlowMist said the malware is specifically designed to identify cryptocurrency-related files stored on compromised devices.

Among its capabilities is the ability to facilitate wallet replacement attacks, in which legitimate wallet software such as Ledger or Trezor is replaced with modified versions capable of capturing recovery phrases or other sensitive credentials. Because victims often believe they are interacting with authentic software, the technique can bypass many of the protections built into hardware wallets.


READ MORE: Hedera DeFi Protocol Bonzo Lend Suffers $9M Oracle Attack


The campaign also demonstrates how phishing operations are becoming increasingly specialized. Instead of indiscriminately stealing passwords, attackers are prioritizing information that provides direct access to digital assets, reflecting the higher financial value associated with cryptocurrency users.

The latest disclosure comes as researchers continue to report more sophisticated malware targeting Apple’s desktop operating system, challenging the long-held perception that macOS users face significantly lower cybersecurity risks than Windows users.

Recent Campaigns Point to a Broader Trend

The SlowMist investigation follows the discovery of several macOS information-stealing campaigns reported this week, including ClickLock Stealer, which repeatedly forces password prompts until users comply, and CrashStealer, which impersonates Apple’s Crash Reporter to gain trust before harvesting credentials.

Taken together, the campaigns suggest attackers are increasingly investing in malware designed specifically for Apple’s ecosystem while refining social engineering techniques that require little technical exploitation.

For users who suspect their device has been compromised, security researchers recommend assuming that all locally stored credentials are exposed. Rather than simply deleting suspicious files, affected users should move cryptocurrency assets using a separate trusted device, perform a clean installation of macOS, rotate passwords, revoke active sessions, replace API and SSH keys where applicable, and download future software only from verified developer sources.

As digital assets become more widely adopted, security experts say protecting wallets increasingly depends on safeguarding the devices that store access credentials, making endpoint security as important as blockchain security itself.


The information presented in this article is intended for informational purposes only and should not be interpreted as financial, investment, or trading advice. Coinspress.com does not promote or advocate for any particular investment strategy, asset, or cryptocurrency project. Cryptocurrency markets are highly volatile and unpredictable – always perform your own research and seek guidance from a qualified financial professional before making any investment decisions.

Author
Alexander Zdravkov

Reporter at CoinsPress

Alexander Zdravkov is a market analyst and crypto journalist with interests in economics, broader financial markets and digital assets. His journey into crypto began more than four years ago, driven by a fascination with the rapid evolution of blockchain technology and the transformative potential of decentralized finance. He began analyzing market cycles and identifying emerging trends before they reach the mainstream. He holds a degree in International Relations - a background that helped shape his broader perspective on global economics, geopolitics, and the interconnected nature of modern financial markets. Whether covering the latest developments in the crypto sector or exploring broader macroeconomic themes, Alexander focuses on giving readers context rather than simply repeating headlines. During his career, he has authored more than 10,000 articles covering cryptocurrencies, traditional finance, and global market developments. His work spans everything from Bitcoin and altcoins to macroeconomic trends influencing risk assets worldwide.

Learn more about crypto and blockchain technology.

Glossary