Share this article

New Malware Targets Apple Mac Computers to Steal and Mine Cryptos

A recently discovered form of malware steals browser cookies and other information on Apple Mac computers to steal cryptocurrencies.

Updated Sep 13, 2021, 8:51 a.m. Published Feb 1, 2019, 2:30 p.m.
Apple Mac

A recently discovered form of malware steals browser cookies and other information on victims' Apple Mac computers to steal cryptocurrencies.

Researchers at cybersecurity firm Palo Alto Networks published a report on Thursday, saying that the malware, dubbed “CookieMiner,” intercepts browser cookies related to cryptocurrency exchanges and wallet service providers’ websites visited by the victims.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

The malicious code targets exchanges and services including Binance, Coinbase, Poloniex, Bittrex, Bitstamp and MyEtherWallet, as well as any website having "blockchain" in its domain name, the researchers found.

The malware also tries to steal credit card information from major issuers, such as Visa, Mastercard, American Express and Discover, as well as saved usernames and passwords in Chrome, iPhone text messages that are backed up to iTunes and crypto wallet keys.

If CookieMiner succeeds at stealing those details, hackers can gain full access to victims’ crypto exchange and wallet accounts to steal funds.

The researchers explained:

“CookieMiner tries to navigate past the authentication process by stealing a combination of the login credentials, text messages, and web cookies.”

MyEtherWallet founder and CEO Kosala Hemachandra told CoinDesk via email: "[MyEtherWallet] is not a cryptocurrency exchange but an interface to interact with the Ethereum blockchain. We do not use cookies so this malware ... will not affect our users as long as they do not save their passwords with Chrome."

CookieMiner has another string to its bow too – it changes a victim's system configuration to maliciously load crypto mining software. The coinminer is similar to a variant that mines monero, but instead targets a lesser-known cryptocurrency called Koto, the researchers said.

The researchers suggested that cryptocurrency users should keep "an eye on their security settings and digital assets to prevent compromise and leakage." They also noted that the malware checks if an application firewall program called Little Snitch is running on a victim’s computer. "If so, it will stop and exit," they said

Monero is by far the most popular cryptocurrency among hackers, though. Last month, a study by college researchers showed that hackers have mined nearly 5 percent of the total monero in circulation.

Deployments of crypto-mining malware are rapidly growing in number. A study from McAfee, published in December, showed that there were nearly 4 million new mining malware threats in the third quarter of 2018 alone, compared to less than 500,000 in 2017 and 2016.

Edit (09:15 UTC, Feb. 7 2019): Updated with comment from MyEtherWallet founder and CEO Kosala Hemachandra.

Apple MacBook image via Shutterstock

More For You

Pudgy Penguins: A New Blueprint for Tokenized Culture

Pudgy Title Image

Pudgy Penguins is building a multi-vertical consumer IP platform — combining phygital products, games, NFTs and PENGU to monetize culture at scale.

알아야 할 것:

Pudgy Penguins is emerging as one of the strongest NFT-native brands of this cycle, shifting from speculative “digital luxury goods” into a multi-vertical consumer IP platform. Its strategy is to acquire users through mainstream channels first; toys, retail partnerships and viral media, then onboard them into Web3 through games, NFTs and the PENGU token.

The ecosystem now spans phygital products (> $13M retail sales and >1M units sold), games and experiences (Pudgy Party surpassed 500k downloads in two weeks), and a widely distributed token (airdropped to 6M+ wallets). While the market is currently pricing Pudgy at a premium relative to traditional IP peers, sustained success depends on execution across retail expansion, gaming adoption and deeper token utility.

More For You

Weaker dollar fails to spur bitcoin gains, but there's a reason for that

A bear

Gold and other hard assets are rallying on dollar weakness, but bitcoin is lagging as markets continue to treat it as a liquidity-sensitive risk asset.

알아야 할 것:

  • Bitcoin has, unusually, not rallied alongside the slide in the U.S. dollar.
  • JPMorgan strategists say the dollar’s weakness is being driven by short-term flows and sentiment, not changes in growth or monetary policy expectations, and they expect the currency to stabilize as the U.S. economy strengthens.
  • Because markets do not view the current dollar decline as a lasting macro shift, bitcoin is trading more like a liquidity-sensitive risk asset than a reliable dollar hedge, leaving gold and emerging markets as the preferred beneficiaries of dollar diversification.