Fun

Mac users beware: AMOS malware clones wallet apps and comes for your crypto

News Feed - 2024-08-23 10:08:56

Christopher Roark10 hours agoMac users beware: AMOS malware clones wallet apps and comes for your cryptoThe AMOS stealer targeting Mac users can now clone Ledger Live software and may soon clone other wallet apps, warns cybersecurity firm Moonlock.1605 Total views6 Total sharesListen to article 0:00AnalysisOwn this piece of crypto historyCollect this article as NFTCOINTELEGRAPH IN YOUR SOCIAL FEEDFollow ourSubscribe onMalware program “Atomic MacOS,” or “AMOS,” now has a new capability that allows it to clone wallet apps and steal cryptocurrency from users.


According to an Aug. 5 report from cybersecurity firm Moonlock Lab, the program is experiencing a resurgence, with the firm spotting it being advertised through Google AdSense. In the advertisements, it masqueraded as popular MacOS programs, including screen sharing app Loom, user interface design tool Figma, VPN Tunnelblick, and instant messaging app Callzy. None of the developers of these apps authorized the fake AMOS malware versions.


Moonlock researchers discovered the malware when they ran across a version that pretended to be Loom. When they clicked the advertisement, it redirected them to smokecoffeeshop.com, which then redirected them again to a fake version of the Loom website. 


The fake version looked exactly like the real one. However, when a user clicked the “Get Loom for free” button, instead of downloading the Legitimate Loom program, it downloaded “a complex version of the AMOS stealer.”Comparison between real (left) and fake (right) version of Loom website. Source: Moonlock Lab


AMOS is not a new program. Cybersecurity firm Cyble reported its existence as early as April 2023. According to Cyble, the program was being sold to cybercriminals on Telegram as a subscription service for $1,000 per month.  


At the time, it was capable of targeting over 50 different crypto wallets, including Electrum, MetaMask, Coinbase, Binance, Exodus, Atomic, Coinomi and others. When the program found any of these wallets on a user’s computer, it stole the wallet’s data, Cyble claimed, implying that the user’s encrypted keyvault file was likely snatched by AMOS.AMOS targeting crypto wallets. Source: Cyble Research and Intelligence Labs


If a keyvault file is stolen, the attacker can drain the user’s wallet, especially if the victim used a weak password when they first created their wallet account.


Moonlock claimed that the software has now apparently been upgraded, as it found a version that “has a novel capability.” AMOS can now “replace a specific crypto wallet app with a clone and easily wipe out victims’ e-wallets.” 


Specifically, it can clone the Ledger Live software used by Ledger hardware wallet owners. Moonlock emphasized that this capability “has never been reported in a version of AMOS before and represents a significant leap forward” for the malicious program.


Ledger devices store their private keys on hardware devices, out of the reach of malware installed on a PC, and users have to confirm each transaction on the device. This makes it difficult for malware to steal crypto from Ledger users. However, the attacker’s intention in cloning Ledger Live may be to display deceptive information on the user’s screen, causing them to mistakenly send their crypto to the attacker. 


Related:Ledger CTO warns crypto users about the dangers of "blind signing"


Even more troubling than the ability to clone Ledger Live, the report notes that future versions of the software may be able to clone other apps. This could potentially include software wallets like MetaMask and Trust Wallet. “If this new version of AMOS can replace Ledger Live with a fake malicious clone,” Moonlock suggested, “it could do the same with other apps.”


Software wallets display all their information directly on the PC monitor, making deceptive displays even more dangerous.


Moonlock claimed to have traced the software to developer Crazy Evil, which advertises itself on Telegram. The group allegedly posted a recruitment ad boasting of the AMOS software’s ability to clone Ledger Live.


Users who run crypto wallet software on a Mac should be aware that AMOS is specifically targeting people like them. This malware is generally distributed through Google Adsense ads, so they may want to be extremely careful when considering whether to download software from a website they found through a banner or display ad. It may appear to be Loom, Callzy or another popular program but in fact is a copy of AMOS.


Magazine: Weird ‘null address’ iVest hack, millions of PCs still vulnerable to ‘Sinkclose’ malware: Crypto-Sec


If in doubt about the authenticity of a website, typing the name of the program into a search engine and scrolling down to the organic results is sometimes an effective way of finding the official website for an app, as scammers usually don’t have the domain authority to rank at the top of organic results for an app’s name.


Google uses filters in an attempt to prevent malware programs from being advertised through its program, but they are not 100% effective.


Malware continues to be a serious threat to crypto users. On Aug. 16, cybersecurity firm Check Point Research discovered a similar “stealer” program that drained crypto through a method called “clipping.” On May 13, Kaspersky Labs discovered malware called “Durian” that was used to attack crypto exchanges.# Bitcoin# Bitcoin Wallet# Wallet# Ethereum# Adoption# Malware# Hardware Wallet# Cybersecurity# Hot walletAdd reaction

News Feed

FX Strategists From Citi Say Euro Could Sink to $0.86 if Macro Turmoil Continues
FX Strategists From Citi Say Euro Could Sink to $0.86 if Macro Turmoil Continues While the euro has found support between 0.96 to 0.97 nominal U.S. dollars per unit, foreign exchan
LBank Exchange Will List THN (Throne) on September 22, 2021
LBank Exchange Will List THN (Throne) on September 22, 2021 press release PRESS RELEASE. INTERNET CITY, DUBAI – LBank Exchange, a global digital asset trading platform, is pr
Indian Government Reveals How It Plans to Tax Cryptocurrency Transactions
Indian Government Reveals How It Plans to Tax Cryptocurrency Transactions India’s ministry of finance has clarified in parliament how the government plans to tax cryptocurre
Bitwise pledges 10% of spot Ether ETF profits to Ethereum developers
Ezra Reguerra12 hours agoBitwise pledges 10% of spot Ether ETF profits to Ethereum developersBitwise launches its spot Ether ETF and pledges 10% of the profits to Ethereum developers via Protocol Guild and PBS Foundation
21Shares launches Injective ETP with staking on Euronext
Derek Andersen6 hours ago21Shares launches Injective ETP with staking on EuronextINJ takes a spot among the largest cryptos with a financial product exposing it to traditional investors.998 Total views1 Total sharesListe
SEI Follows SUI; Token Charges Higher With 18% Rally — Is $0.65 Possible?
Este artículo también está disponible en español. A little over a year since its debut, the SEI token has experienced remarkable growth, looking to break into the top 50
Solana releases mainnet beta update v1.17.31 to resolve congestion issues
Prashant Jha20 minutes agoSolana releases mainnet beta update v1.17.31 to resolve congestion issuesThe Solana Foundation claimed ongoing network congestion could be attributed to the high demand for Solana block space an
Ethereum Dev Says The Merge Could Be Delayed a Few Months, ‘Strongly Suggests’ Not Investing in ETH Mining Rigs
Ethereum Dev Says The Merge Could Be Delayed a Few Months, "Strongly Suggests" Not Investing in ETH Mining Rigs According to Ethereum developer Tim Beiko, The Merge is likely to be
Bitcoin’s Hashrate Hits an All-Time High Nearing 300 Exahash per Second
Bitcoin"s Hashrate Hits an All-Time High Nearing 300 Exahash per Second While Bitcoin’s mining difficulty was expected to decrease two days ago on June 8, instead the diffic
Turner Wright8 hours ago‘The SEC has violated due process’ — Coinbase CLO on motion to dismiss lawsuitLawyers for Coinbase cited precedent from the SEC v. Ripple case, in which a judge ruled that XRP largely did no
Microstrategy Buys 6,455 More Bitcoin — Now Holds 138,955 BTC
Microstrategy Buys 6,455 More Bitcoin — Now Holds 138,955 BTC Microstrategy has purchased 6,455 bitcoins for approximately $150 million at an average price of $23,238 per coin. W
Visa and Mastercard: A boon for wallet holders, a threat to crypto exchanges?
Andrew Singer8 hours agoVisa and Mastercard: A boon for wallet holders, a threat to crypto exchanges?Crypto debit cards aren’t new. But Visa supports 40 cryptocurrencies across an enormous network. “That’s a big de