Cyber Security News

New ModStealer Evade Antivirus Detection to Attack macOS Users and Steal Sensitive Data

A sophisticated new cross-platform information stealer known as ModStealer has emerged, targeting macOS users and demonstrating concerning capabilities to evade Apple’s built-in security mechanisms.

The malware represents the latest evolution in macOS-focused threats, which have seen a dramatic surge throughout 2024 and continue accelerating into the current year.

ModStealer follows established patterns seen in other macOS stealers but introduces unique persistence mechanisms that set it apart from predecessors like Atomic Stealer.

The malware primarily targets developers and cryptocurrency holders through social engineering campaigns involving fake job advertisements and recruitment opportunities, taking advantage of these groups’ valuable digital assets and frequent interaction with online development resources.

Initial reports from cybersecurity firm Mosyle indicate that ModStealer first appeared on VirusTotal approximately one month ago.

Moonlock analysts identified the malware’s cross-platform nature, enabling it to compromise macOS, Windows, and Linux systems simultaneously.

This versatility makes ModStealer particularly dangerous, as threat actors can deploy unified campaigns across multiple operating systems rather than maintaining separate malware variants for each platform.

The malware’s capabilities extend beyond typical data theft operations. ModStealer can infiltrate over 50 browser extensions across Chrome and Safari platforms, with Safari targeting being relatively uncommon among information stealers.

The malware extracts data from cryptocurrency wallet extensions, captures clipboard contents containing seed phrases and private keys, takes screenshots of visible user data, and harvests saved browser information including local storage databases, cookies, and stored credentials.

Advanced Persistence Through LaunchAgent Abuse

ModStealer’s most notable technical innovation lies in its persistence mechanism on macOS systems.

Rather than employing traditional persistence methods, the malware leverages Apple’s native launchctl utility to embed itself as a LaunchAgent within the system’s startup processes.

This approach allows ModStealer to maintain long-term, undetectable presence on compromised Mac devices by masquerading as legitimate system processes.

The malware creates hidden payload files such as “sysupdater.dat” to store its components while establishing persistence through macOS LaunchAgent configurations.

This technique effectively bypasses many detection systems that focus on monitoring unauthorized modifications to system files or registry entries.

By utilizing Apple’s own tools and frameworks, ModStealer presents itself as legitimate system activity, making detection significantly more challenging for both automated security solutions and manual analysis.

A VirusTotal user comment reveals how they were contacted by a fake recruiter impersonating a known LinkedIn account (Source – Moonlock)

Once established, ModStealer maintains communication with command-and-control servers to receive additional instructions, extract collected data, and potentially facilitate lateral movement within compromised networks.

This persistent connection enables threat actors to continuously harvest sensitive information and adapt their operations based on the specific environment of each victim system.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago