Experts: New Cthulhu Malware Steals MacOS Crypto Wallet Keys

4 Min Read Tags:

  • Cado Security analysts warn MacOS users about new malware called Cthulhu Stealer.
  • Cthulhu Stealer targets cryptocurrency wallet keys and personal data.
  • The malware is distributed as Malware-as-a-Service (MaaS) via a Telegram group.
  • Rental cost for the malware is $500 per month, with additional profit from stolen data.
  • The malware disguises itself as legitimate software such as CleanMyMac, GTA IV, or Adobe GenP.
  • Cthulhu Stealer is likely a modified version of the previously identified Atomic Stealer.
  • Recent issues reported by partners of the malware’s main developer, Balaclavv, have led to its blocking on some platforms.

New Malware Cthulhu Stealer Targets MacOS Cryptocurrency Wallets

Cado Security analysts have uncovered a new threat to MacOS users with the emergence of the Cthulhu Stealer malware. This malicious software, designed to steal personal data and cryptocurrency wallet keys, is being distributed under the Malware-as-a-Service (MaaS) model. The creators rent out the malware for $500 per month through a Telegram group, making it a significant concern for the crypto community.

How Cthulhu Stealer Operates

Cthulhu Stealer is distributed as an Apple Disk Image (DMG) file, which disguises itself as legitimate software like CleanMyMac, Grand Theft Auto IV, or Adobe GenP. Once installed on a user’s system, the primary goal of this malware is to extract personal information from various sources. These include gaming accounts, browsers, cryptocurrency wallets, and other data storage locations.

Connections to Previous Malware

Experts have noted similarities between Cthulhu Stealer and another piece of hacker software called Atomic Stealer, which was also designed to steal data from MacOS systems. Discovered by analysts in 2023, Atomic Stealer operated in a similar fashion. This suggests that Cthulhu Stealer might be a modified version of the earlier malware, enhancing its capabilities and potentially expanding its reach.

Distribution and Monetization

The developers of Cthulhu Stealer use a unique distribution scheme. They have set up a Telegram group where they offer the malware for rent at $500 per month. This business model, known as Malware-as-a-Service (MaaS), allows them to monetize their creation by granting access to other cybercriminals. In addition to the subscription fee, the developers take a percentage of the stolen data’s value, providing deployment and technical support to their clients.

Challenges Faced by the Creators

Despite their sophisticated operation, the creators of Cthulhu Stealer have faced recent setbacks. According to experts, partners of the main developer, known by the alias Balaclavv, have reported payment delays. This has led to the malware being blocked on at least one platform that sells malicious software.

Conclusion

The discovery of Cthulhu Stealer highlights the ongoing threat to MacOS users, particularly those involved in cryptocurrency. As this malware targets valuable keys and personal data, it is crucial for users to remain vigilant and employ robust security measures. The evolving nature of these threats underscores the importance of staying informed about the latest developments in cybersecurity to protect digital assets effectively.

TAGGED:
Canary Capital Launches First US Spot TRX ETF With Staking

Canary Capital launched the Canary Staked TRX ETF on Cboe BZX under ticker TRXS on Sept. 9, 2026, offering direct TRX exposure and staking rewards.

5 Min Read
Anthropic Models 3 US Economic Scenarios Through 2030

Anthropic published a model outlining three scenarios for the U.S. economy through 2030, with its extreme scenario suggesting annual GDP growth could reach 15% alongside historically high unemployment.

7 Min Read
Robinhood CEO Says Companies Cannot Control Tokenization of Their Shares

In September 2026, Robinhood CEO Vlad Tenev said companies cannot prevent third-party products linked to their shares, defending 1:1 share-backed Stock Tokens after AMC CEO Adam Aron challenged their legality.

5 Min Read
Germany Will Change Crypto-Asset Tax Rules in 2027, Media Reports

Germany’s draft crypto tax reforms would from Jan. 1, 2027, tax profits on covered assets acquired after Dec. 31, 2026, regardless of holding period, while platforms would begin withholding tax…

5 Min Read
Vitalik Buterin Says Recursive STARKs Could Cut Ethereum Private, Post-Quantum Transaction Costs

On Sept. 9, Ethereum co-founder Vitalik Buterin explained EIP-8288, a proposal to aggregate STARK proofs and cryptographic signatures at the mempool level, potentially reducing costs without changing the EVM.

6 Min Read