started · updated
Cybersecurity researchers warn of new malware targeting cryptocurrency users
Cybersecurity researchers have identified two distinct malware campaigns targeting cryptocurrency users through deceptive software.
Kaspersky reported an updated version of the MacSync infostealer targeting macOS. The malware uses a complex infection chain, sometimes utilizing public iCloud calendar entries to host malicious components. Once installed, it installs both an infostealer and a backdoor disguised as the Finder application. MacSync is capable of harvesting browser histories, cookies, saved credentials, and data from cryptocurrency wallets, Telegram, and the device Keychain. It can also replace legitimate cryptocurrency wallet extensions with malicious versions.
Separately, HP revealed a campaign involving Needle Stealer, where cybercriminals disguised malware as an AI-powered cryptocurrency trading agent. Between April and June 2026, attackers targeted users searching for automated AI trading tools. After downloading the software, the malware would remove genuine browser wallet extensions—such as MetaMask, Coinbase Wallet, and Phantom—and replace them with malicious copies. When victims entered their passwords into these fake extensions, the credentials were sent to attacker-controlled servers. The installation packages used Microsoft-signed software to bypass initial security checks.
Entities
HP · Kaspersky · MacSync · Needle Stealer