Mac Users Beware: ‘Realst’ Malware Emerges, Specifically Targeting Crypto Wallets

2023-7-26 16:00

A new and challenging form of malware dubbed “Realst” currently targets macOS and Windows users, posing a particular risk to Apple computer owners.

This cunning malware disguises itself as fake blockchain games, such as Brawl Earth and Dawnland, and spreads through social media promotions and direct messages, putting unwary users in harm’s way.

When unwary victims fall into its trap and use the offered access codes to access the threat actor’s website, their devices become prone to attack.

Realst demonstrates its destructive goal by silently stealing sensitive data from web browsers and cryptocurrency wallet apps, exposing users’ personal information and digital assets.

Security researcher iamdeadlyz discovered Realst, which was first thought to target macOS users, but it has since been found that Windows users are also at risk.

RedLine Stealer, AsyncRAT, and Raccoon Stealer are just a few of the malware strains introduced onto Windows workstations by the threat, making it tough to detect.

Unraveling Realst’s Stealthy Approach

SentinelOne, a cybersecurity organization, examined 59 “Mach-O” samples of Realst and discovered a range of active macOS variants, each showing signs of rapid development. This rapid evolution increases the difficulty of tracking and combating malware effectively.

Realst infects devices through deceptive PKG installers and DMG disk files for macOS users, cunningly concealed to resemble genuine games or decoy software. When malware is implanted, it takes hold and gives unauthorized users access to personal data and digital wallets.

An alarming element of Realst is the presence of a cross-platform Firefox information stealer known as “game.py.” This script efficiently harvests sensitive data from users’ web browsers, providing threat actors with a wealth of exploitable information.

Moreover, Realst employs “chainbreaker,” an open-source macOS keychain database, to obtain stored passwords and internet account credentials in clear text format, heightening the risk to victims.

Experts Call For Vigilance And Caution Against Malware

The desire to steal cryptocurrencies is the main driver behind these attacks. Unaware users are seen as a tempting target by hostile actors as digital assets become more popular and valuable.

Experts emphasize the importance of caution while installing software from unknown sources, mainly social media adverts and direct messages, as malware adapts and spreads. To stay safe, users must rely solely on official app stores and verified websites for their software needs.

By implementing these safety measures and raising awareness about the Realst threat, users can better protect themselves from this malicious menace.

Featured image from The SSL Store

origin »

Bitcoin price in Telegram @btc_price_every_hour

ITAM Games (ITAM) на Currencies.ru

$ 0.0099634 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 4.81 %
Cегодня L: $0.0099634 - H: $0.0099634
Капитализация $0 Rank 6353
Цена в час новости $ 0.0075864 (31.33%)

users malware realst unwary such brawl dawnland

users malware → Результатов: 126


SecureBrain joins the PolySwarm decentralized cyber threat intel marketplace

PolySwarm, a crowd-sourced marketplace for threat intelligence and malware detection, has announced SecureBrain Corporation as its latest threat detection partner. SecureBrain’s threat detection technology will be active on PolySwarm starting this month February, detecting threats and helping users get determinations on potentially malicious files and URLs.

2020-2-10 14:06


Kaspersky: Lazarus Hackers To Steal Crypto Using Telegram in ‘Operation AppleJesus Sequel’

The Moscow-based cybersecurity firm Kaspersky has informed cryptocurrency users that North Korean hackers have developed new ways of delivering malware through Telegram. Kaspersky has been looking at the latest attacks of the Lazarus Group, a North Korea-related cybercrime organization that has also conducted the AppleJesus attack on some of the most important crypto exchanges in […]

2020-1-10 22:16


Фото:

Hackers hid malware in a fake trading app to steal your cryptocurrency

Security researchers have uncovered a knock-off cryptocurrency trading website designed to steal the funds of unwitting victims. Cybercriminals have created a website that imitates the Cryptohopper cryptocurrency trading platform to distribute malware that could steal personal information, hijack your clipboard, and crypto-jack your system, Bleeping Computer reports.

2019-6-6 16:16


New XMRig Cryptojacking Malware Found by Trend Micro Is Attacking Devices Around the World

The cryptocurrency investors of the world are probably pretty happy to see the Coinhive crypto mining script offline, but that doesn’t mean that cryptojacking is over. In fact, recent research by Trend Micro indicates that there’s a new collection of malware that is going after users’ hardware, in an effort to mine cryptocurrency. According to […]

2019-6-5 02:11