New MacStealer macOS Malware Steals iCloud Keychain Data and Passwords

Share:

A new information-stealing malware has set its sights on Apple’s macOS operating system to siphon sensitive information from compromised devices.

Dubbed MacStealer, it’s the latest example of a threat that uses Telegram as a command-and-control (C2) platform to exfiltrate data. It primarily affects devices running macOS versions Catalina and later running on M1 and M2 CPUs.

“MacStealer has the ability to steal documents, cookies from the victim’s browser, and login information,” Uptycs researchers Shilpesh Trivedi and Pratik Jeware said in a new report.

First advertised on online hacking forums for $100 at the start of the month, it is still a work in progress, with the malware authors planning to add features to capture data from Apple’s Safari browser and the Notes app.

In its current form, MacStealer is designed to extract iCloud Keychain data, passwords and credit card information from browsers like Google Chrome, Mozilla Firefox, and Brave. It also features support for harvesting Microsoft Office files, images, archives, and Python scripts.

 

 

The exact method used to deliver the malware is not known, but it is propagated as a DMG file (weed.dmg) that, when executed, opens a fake password prompt to harvest the passwords under the guise of seeking access to the System Settings app.

MacStealer is one of several info-stealers that have surfaced just over the past few months and adds to an already large number of similar tools currently in the wild.

MacStealer macOS Malware

This also includes another piece of new C#-based malware called HookSpoofer that’s inspired by StormKitty and comes with keylogging and clipper abilities and transmits the stolen data to a Telegram bot.

Another browser cookie-stealing malware of note is Ducktail, which also uses a Telegram bot to exfiltrate data and re-emerged in mid-February 2023 with improved tactics to sidestep detection.

This involves “changing the initial infection from an archive containing a malicious executable to an archive containing a malicious LNK file that would start the infection chain,” Deep Instinct researcher Simon Kenin said earlier this month.

WEBINAR

Discover the Hidden Dangers of Third-Party SaaS Apps

Are you aware of the risks associated with third-party app access to your company’s SaaS apps? Join our webinar to learn about the types of permissions being granted and how to minimize risk.

RESERVE YOUR SEAT

Stealer malware is typically spread through different channels, including email attachments, bogus software downloads, and other social engineering techniques.

To mitigate such threats, it’s recommended that users keep their operating system and security software up to date and avoid downloading files or clicking links from unknown sources.

“As Macs have become increasingly popular in the enterprise among leadership and development teams, the more important the data stored on them is to attackers,” SentinelOne researcher Phil Stokes said last week.

 

(c) Ravie Lakshmanan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
12:27 am, Jul 7, 2025
weather icon 17°C
L: 16° | H: 18°
broken clouds
Humidity: 71 %
Pressure: 1007 mb
Wind: 10 mph WNW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:52 am
Sunset: 9:18 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
16° | 18°°C 0.99 mm 99% 13 mph 85 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
13° | 24°°C 0.2 mm 20% 11 mph 76 % 1020 mb 0 mm/h
Wed Jul 09 10:00 pm
weather icon
15° | 26°°C 0 mm 0% 6 mph 66 % 1023 mb 0 mm/h
Thu Jul 10 10:00 pm
weather icon
19° | 31°°C 0 mm 0% 8 mph 63 % 1024 mb 0 mm/h
Fri Jul 11 10:00 pm
weather icon
20° | 30°°C 0 mm 0% 12 mph 54 % 1023 mb 0 mm/h
Today 1:00 am
weather icon
16° | 17°°C 0 mm 0% 9 mph 71 % 1007 mb 0 mm/h
Today 4:00 am
weather icon
16° | 17°°C 0.31 mm 31% 8 mph 75 % 1007 mb 0 mm/h
Today 7:00 am
weather icon
14° | 15°°C 0.99 mm 99% 10 mph 85 % 1008 mb 0 mm/h
Today 10:00 am
weather icon
17° | 17°°C 0.33 mm 33% 12 mph 53 % 1011 mb 0 mm/h
Today 1:00 pm
weather icon
22° | 22°°C 0 mm 0% 13 mph 37 % 1012 mb 0 mm/h
Today 4:00 pm
weather icon
20° | 20°°C 0 mm 0% 10 mph 41 % 1013 mb 0 mm/h
Today 7:00 pm
weather icon
20° | 20°°C 0 mm 0% 7 mph 45 % 1014 mb 0 mm/h
Today 10:00 pm
weather icon
17° | 17°°C 0 mm 0% 11 mph 49 % 1015 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,673.42
0.87%
Ethereum(ETH)
€2,183.43
2.04%
Tether(USDT)
€0.85
0.00%
XRP(XRP)
€1.93
2.32%
Solana(SOL)
€129.06
2.82%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.146015
4.53%
Shiba Inu(SHIB)
€0.000010
2.86%
Pepe(PEPE)
€0.000008
3.59%
Scroll to Top