New macOS malware poses as legitimate apps to steal passwords and personal data — how to stay safe

Malware
(Image credit: solarseven/Shutterstock)

While Apple's Macs aren't targeted by hackers as much as Windows PCs, they aren't impenetrable. Security researchers recently uncovered malware dubbed "Cthulhu Stealer" that impersonates popular apps to harvest passwords and steal data from macOS users. 

As first reported by The Hacker News, Cado Security pushed out a public warning this week about Cthulhu Stealer, a malware-as-a-service targeting macOS users launched in late 2023 that sells for $500 a month. "The malware is written in Golang and disguises itself as legitimate software," said Cado Security researcher Tara Gould. 

To trick users into installing it, it's appeared as software programs like CleanMyMac, Grand Theft Auto IV, or Adobe GenP, an open-source tool some Adobe users employ to get around having a Creative Cloud subscription. The malware comes packaged as a disk image (DMG) file that contains a pair of binaries, which lets it attack both Intel and Apple Silicon Macs depending on which architecture it detects. 

When a user tries to open the fake app, macOS's built-in security feature, Gatekeeper, warns that the software is unsigned. If the user opts to bypass Gatekeeper protections and let it run anyway, they're given an otherwise legitimate-looking prompt to enter their system password, followed by a second prompt for the MetaMask cryptocurrency wallet. Once it has the necessary permissions, Cthulhu Stealer can siphon a wide range of sensitive data, including saved passwords from iCloud Keychain, web browser cookies and Telegram account information. 

"The main functionality of Cthulhu Stealer is to steal credentials and cryptocurrency wallets from various stores, including game accounts," Gould explained. 

It's an osascript-based technique that we've seen in infostealers and malware before like Atomic Stealer, Cuckoo, MacStealer, and Banshee Stealer. But even if Cthulhu Stealer isn't the most sophisticated malware out there, it still poses a serious threat to Mac users who could stumble into this trap. 

How to stay safe from Mac malware

So what can you do to keep the best Macs protected from malware like Cthulhu Stealer? First and foremost, be vigilant about the apps you download and do your due diligence to make sure whoever you're downloading it from is who they say they are. While your Mac comes with built-in antivirus software in the form of XProtect, consider using that in tandem with one of the best Mac antivirus software solutions. Paid antivirus software is updated more regularly and will often throw in a VPN or password manager to help you stay safe online.

Apple is also working on making it harder to bypass Gatekeeper protections with macOS Sequoia, which is expected to roll out in mid-September. Rather than being able to override Gatekeeper warnings by Control-clicking, users will instead have to go through System Settings to allow unsigned software to run. Hopefully, the annoyance of going through an extra step will be enough of a deterrent to make users think twice before running potentially dangerous apps.

More from Tom's Guide

Alyse Stanley
News Editor

Alyse Stanley is a news editor at Tom’s Guide, overseeing weekend coverage and writing about the latest in tech, gaming, and entertainment. Before Tom’s Guide, Alyse worked as an editor for the Washington Post’s sunsetted video game section, Launcher. She previously led Gizmodo’s weekend news desk and has written game reviews and features for outlets like Polygon, Unwinnable, and Rock, Paper, Shotgun. She’s a big fan of horror movies, cartoons, and roller skating.

Read more
Malware
New macOS malware uses Apple's own code to quietly steal credentials and personal data — how to stay safe
MacBook Pro 2021 (16-inch) on a patio table
Millions of Mac owners urged to be on alert for info-stealing malware
MacBook Pro 2021 (16-inch) on a patio table
Macs under attack from dangerous malware targeting digital wallets and Apple’s Notes app — how to stay safe
A hacker typing quickly on a keyboard
Hackers are posing as Apple and Google to infect Macs with malware — don’t fall for these fake browser updates
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
One phone with skull and crossbones on screen among several other clean-looking phones.
Malicious iPhone apps are spreading screenshot-reading malware on the Apple App Store — how to stay safe
Latest in Malware & Adware
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Malware
Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs
An FBI agent typing on a computer
FBI issues warning to millions of Americans to avoid these websites that can steal your passwords and banking info
A hacker typing quickly on a keyboard
New MassJacker malware is hijacking digital wallets to steal large sums from users
A person trying to set up a new Wi-Fi router
Thousands of TP-Link routers have been infected by a botnet to spread malware
A smartphone screen displaying the Android name and logo next to a sign reading 'MALWARE'.
Fake Google Play Store pages are spreading Trojan malware that can steal your financial data
Latest in News
Tom Hiddleston as Robert Laing in "High Rise" now streaming on Netflix
5 best Netflix movies in March you haven't watched yet
iPhone 16 with Apple Intelligence logo for iOS 18.1
iOS 18.4: All the newest Apple Intelligence features coming to your iPhone
Maria Debska in "Just One Look" now streaming on Netflix
3 best Netflix shows in March you haven't watched yet
Split image featuring the Galaxy S25 Edge (left) and Galaxy S25 Ultra (right)
Samsung Galaxy S25 Edge just tipped for two Galaxy S25 Ultra-level features
Wolfenstein: The Old Blood
Amazon is giving away a ton of free games for its Big Spring Sale — here’s how to claim yours
A TV with the Netflix logo sits behind a hand holding a remote
Netflix is rolling out a big video quality upgrade — what you need to know