Tuesday, September 15, 2026
Follow on LinkedIn

Hackers Attacking macOS Users With Fake Ledger Apps to Deploy Malware

Cybercriminals are increasingly targeting cryptocurrency users through sophisticated malware campaigns that exploit the trust placed in cold wallet management applications.

Since August 2024, threat actors have been distributing malicious clones of Ledger Live, the widely-used application for managing cryptocurrency through Ledger hardware wallets.

These attacks represent a significant evolution in cryptocurrency-focused malware, moving beyond simple data theft to directly targeting users’ seed phrases and wallet funds.

The malware campaigns initially focused on stealing passwords, notes, and wallet details to assess victims’ crypto holdings without being able to extract funds directly.

However, within less than a year, attackers have developed sophisticated phishing mechanisms capable of stealing seed phrases, effectively emptying victims’ wallets within seconds of compromise.

The threat landscape has expanded to include multiple active campaigns simultaneously targeting macOS users.

Moonlock analysts identified four distinct malware campaigns currently exploiting fake Ledger applications, with threat actors continuously refining their techniques to bypass security measures.

The research reveals a concerning trend where cybercriminals are not only improving their technical capabilities but also sharing methodologies across different groups, accelerating the development of more sophisticated attacks.

The impact extends beyond individual victims, as these campaigns threaten the broader cryptocurrency ecosystem’s security foundation.

Cold wallets like Ledger devices were specifically designed to provide offline security for digital assets, making them attractive targets for cybercriminals seeking to undermine what many consider the gold standard of cryptocurrency storage.

Ledger live wallet hack timeline (Source – Moonlock)

The success of these attacks could erode user confidence in hardware wallet solutions and potentially drive adoption toward less secure alternatives.

Odyssey Stealer: The Technical Breakthrough

The most significant advancement in these malware campaigns came through a threat actor known as “Rodrigo,” who developed the Odyssey stealer.

This malware represents a technical turning point by successfully bypassing Ledger Live’s built-in security defenses through an elaborate phishing scheme that has been active since March 19, 2025.

The Odyssey stealer employs a sophisticated infection mechanism that begins by retrieving the victim’s username from the ~/.username path.

Custom NS window (Source – Moonlock)

The malware’s main Mach-O file then processes this information and passes it to an HTML phishing page displayed to the victim.

The technical implementation reveals careful attention to creating a convincing user experience that mimics legitimate Ledger Live functionality.

The phishing page presents a deceptive “critical error” message claiming that users must enter their 24-word seed phrase to resolve account issues.

Once victims comply, the seed phrase is immediately transmitted to an attacker-controlled command-and-control server using a specific URL structure: /ledgerseed//.

This method ensures that both the victim’s identity and their complete wallet recovery information are captured simultaneously.

The malware’s code demonstrates sophisticated evasion techniques, including virtual machine detection to avoid analysis in sandbox environments.

JandiInstaller (Source – Moonlock)

The binary checks for “QEMU” or “VMware” strings using system profiler commands, terminating execution if a virtual environment is detected.

This technical sophistication indicates that the developers possess advanced knowledge of both macOS systems and security research methodologies, making detection and analysis significantly more challenging for cybersecurity professionals.

Equip your SOC team with deep threat analysis for faster response -> Get Extra 𝗦𝗮𝗻𝗱𝗯𝗼𝘅 𝗹𝗶𝗰𝗲𝗻𝘀𝗲𝘀 for Free

Tushar Subhra Dutta
Tushar Subhra Dutta
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Cyber Security Guide

Latest Cyber News

Expert Talks