A dangerous new malware is targeting Macs of all kinds — here's how to stay safe

how to, android, a dangerous new malware is targeting macs of all kinds — here's how to stay safe

A dangerous new malware is targeting Macs of all kinds — here’s how to stay safe

Hackers have been observed targeting Mac devices running on both Intel and ARM silicon with brand new infostealer malware.

Mac security provider Kandji discovered the malware and dubbed it Cuckoo. “This malware queries for specific files associated with specific applications, in an attempt to gather as much information as possible from the system,” the researchers said in their report.

Among the information it pulls is hardware information, currently running processes, and installed applications. Furthermore, Cuckoo is capable of taking screenshots, harvesting data from iCloud Keychains, Apple notes, web browsers, different apps (Discord, Telegram, Steam, and more), and cryptocurrency wallets.

Russia, or China?

To distribute the malware, the threat actors set up a number of malicious sites, where the code is advertised as a program for ripping music from streaming services and converting it into .MP3. It is also being advertised as having both a free and a paid version.

While the researchers did not explicitly attribute the campaign to any particular threat actor, they did note that the infostealer fails to run if the infected device is located in Armenia, Belarus, Kazakhstan, Russia, and Ukraine, possibly hinting an affiliation with Russia. However, they also noted that Cuckoo establishes persistence via LaunchAgent, which was already seen in RustBucket, XLoader, JaskaGO, and a backdoor similar to ZuRu – a Chinese threat actor.

Further adding credence to the China theory is the fact that the malware was signed with a legitimate Chinese developer ID:

“Each malicious application contains another application bundle within the resource directory,” the researchers said. “All of those bundles (except those hosted on fonedog[.]com) are signed and have a valid Developer ID of Yian Technology Shenzhen Co., Ltd (VRBJ4VRP).”

“The website fonedog[.]com hosted an Android recovery tool among other things; the additional application bundle in this one has a developer ID of FoneDog Technology Limited (CUAU2GTG98).”

Via The Hacker News

More from TechRadar Pro

    OTHER NEWS

    19 minutes ago

    Did you know Paul Skenes was an Air Force cadet? MLB phenom highlights academies' inconsistent policy

    22 minutes ago

    A look at what could be the future for postpartum care in America

    22 minutes ago

    The jawbone of washed-up whale in New Zealand was removed with chainsaw and stolen

    22 minutes ago

    A statement cake, dessert bar and flowers: Inside Married At First Sight star Kerry Balbuziente's lavish baby shower with husband Johnny

    22 minutes ago

    Married At First Sight star Ines Basic is convinced she belonged to a 'tribe of vampires' in her past life and can only marry a fellow bloodsucker

    22 minutes ago

    Australian Swifties flock to Europe to catch Taylor Swift's revamped Eras Tour: 'I'm dreaming about it!'

    23 minutes ago

    Mauricio Pochettino will head for Chelsea future talks in strong position if he breaks cycle

    23 minutes ago

    Selena Gomez dazzles at Cannes Film Festival premiere of 'Emilia Perez' in a stunning black and white gown

    23 minutes ago

    Munster drops

    24 minutes ago

    Ireland and Lions Rugby great Tony O’Reilly dies aged 88

    24 minutes ago

    Cannes Film Festival: Australian actress Cate Blanchet stuns in gold number on red carpet after film success

    25 minutes ago

    Beyond Meat urges investors to look past bumpy Q1, says new US burger could reignite sales

    27 minutes ago

    Video: Moment security guard kicks Oxford students and shuts the door on their heads as they lie on the floor covered in fake blood for 'die-in' protesting against Israel's actions in Gaza

    29 minutes ago

    Argentine president Javier Milei in Spain for far-right conference

    29 minutes ago

    Air Quality Experts Prepare For A Hazy "New Normal" As Wildfires Rage Canada

    29 minutes ago

    Usyk is moved to tears as he talks about his supportive late dad

    29 minutes ago

    Waters wins in Perth after Mostert time penalty

    29 minutes ago

    Ancient Chesapeake site challenges timeline of humans in the Americas

    29 minutes ago

    ‘SNL': Sabrina Carpenter Brings Swanky ‘Espresso' to Late Night

    29 minutes ago

    NBA Game 7 schedule today: Everything to know about Sunday's elimination playoff games

    31 minutes ago

    ‘Hit Man’ Director Richard Linklater Laments Hollywood’s “Sexless Characters, Superheroes Without Genitalia”

    31 minutes ago

    ‘Emilia Pérez’ Star Karla Sofía Gascón On How Movie Champions Trans Rights: “We’re Just Normal People” — Cannes

    34 minutes ago

    Video: Wes Streeting forgets Labour's six election pledges live on TV in embarrassing moment

    34 minutes ago

    Mother who exposed South West Water parasite scandal says firm 'have lots of questions to answer' as locals beg tourists to return after company banned anyone from replying to £550,000-a-year boss's video apology

    34 minutes ago

    Michelle Keegan and Mark Wright enjoy a romantic trip to a winery in Australia as she continues filming season two of Ten Pound Poms

    35 minutes ago

    Calls for funding towards the ‘entrepreneurial space’

    35 minutes ago

    How Long Does Carpal Tunnel Syndrome Usually Last? A Review By Doctors

    35 minutes ago

    Kraft Heinz Could Sell Oscar Mayer: What It Means for Investors

    35 minutes ago

    Ireland has a new crop of 'celebrity candidates' - but what do people think of voting for them?

    36 minutes ago

    Sea Is Making a Big Move in E-Commerce -- the Same Move That Catalyzed Growth for MercadoLibre

    36 minutes ago

    Welcome to a once notorious maximum security prison

    36 minutes ago

    Bud Anderson, Last of World War II’s ‘Triple Ace’ Pilots, Dies at 102

    37 minutes ago

    We Rewatched House Of The Dragon Season 1 And Here's What We Noticed

    39 minutes ago

    Emma Raducanu withdraws from French Open qualifying

    39 minutes ago

    Lenovo Yoga 7i 2-in-1 16-inch (2024) review: A MacBook user gives Windows a whirl

    39 minutes ago

    Listen to Robert ‘Pops’ Popwell rip it up on The Crusaders’ Sweet ’N’ Sour

    39 minutes ago

    5 best classic movies just added to Prime Video with 95% or higher on Rotten Tomatoes

    39 minutes ago

    POK will be in India after BJP wins polls, UP CM Yogi says in Maharashtra

    39 minutes ago

    Exercise becomes so much easier once you stop thinking of it as 'working out'

    42 minutes ago

    Smoking dope at home but tested positive at work. This legal case provides clarity for employers, employees

    Kênh khám phá trải nghiệm của giới trẻ, thế giới du lịch