MacOS Malware Campaign Steals Cryptocurrency Wallets Using Social Engineering
A sophisticated macOS malware campaign has been uncovered by researchers, using social engineering tactics to deceive users into running malicious commands in Terminal. The attack installs a Node.js backdoor that relies on EtherHiding, a technique for storing command-and-control configuration inside Ethereum smart contracts.
The main objectives of the attack are to steal cryptocurrency wallets and developer credentials. Researchers found an attack chain involving a fake macOS update page, a Node.js RAT, an infostealer, and a malicious Chrome extension.
On-chain analysis revealed two Ethereum configuration contracts and traced associated funding through major exchanges, including KuCoin and Binance. The investigation also exposed a professional laundering pipeline used to transfer stolen cryptocurrency assets.