Technology
This sneaky malware is after your passwords and personal data
Apple Macs have historically been targeted less by hackers than Windows devices, but this trend is shifting. In recent months, there has been an increase in malware specifically targeting macOS while leaving Windows systems unaffected.
Security researchers uncovered a new threat called “Cthulhu Stealer,” which has emerged, impersonating popular apps to harvest passwords and steal data from macOS users.
The perception of Macs being inherently more secure is evolving as cybercriminals increasingly develop malware for Apple’s operating system. While Macs still face fewer overall threats compared to Windows PCs, the gap is narrowing.
GET SECURITY ALERTS, EXPERT TIPS – SIGN UP FOR KURT’S NEWSLETTER – THE CYBERGUY REPORT HERE
How this ‘malware-as-a-service’ targets your Mac
Cthulhu Stealer malware has been available under a malware-as-a-service (MaaS) model for $500 a month since late 2023, Cado Security discovered.
“Cthulhu Stealer is an Apple disk image (DMG) that is bundled with two binaries, depending on the architecture,” Cado Security researcher Tara Gould said. “The malware is written in Golang and disguises itself as legitimate software.”
The malware pretends to be legitimate software, mimicking programs like CleanMyMac, Grand Theft Auto IV and Adobe GenP. Adobe GenP, in particular, is an open-source tool used to bypass Adobe’s Creative Cloud service and activate apps without paying.
Once you install the malware disguised as a legit app and try to open it, macOS will warn you that it isn’t reliable. Ignoring the warning and continuing will prompt you to enter your password. After that, you’ll see a second prompt asking for your MetaMask password. The malware then creates a directory in ‘/Users/Shared/NW’ and stores the credentials in text files. Chainbreak is used to dump Keychain passwords, which are saved in a file called Keychain.txt.
With the required permissions in place, Cthulhu Stealer can grab a wide range of sensitive data, including saved passwords from iCloud Keychain, web browser cookies and even Telegram account details.
“The main functionality of Cthulhu Stealer is to steal credentials and cryptocurrency wallets from various stores, including game accounts,” Gould explained.
4.3 MILLION AMERICANS EXPOSED IN MASSIVE HEALTH SAVINGS ACCOUNT DATA BREACH
Hackers are preying on Mac users
There has been an increase in malware and vulnerabilities affecting Mac users. Recently, researchers at Cisco Talos discovered a vulnerability in Microsoft apps that could allow hackers to steal all your data and gain control of your system.
Plus, a stealer malware called Banshee is targeting over 100 browsers on Mac devices to steal passwords, cryptocurrency and personal data. These threats are in addition to the numerous data breaches we’ve seen throughout the year. This should act as a reminder that you need to take your cybersecurity seriously.
WHAT IS ARTIFICIAL INTELLIGENCE (AI)?
MASSIVE SECURITY FLAW PUTS MOST POPULAR BROWSERS AT RISK ON MAC
5 tips to protect yourself from Mac malware
Follow these essential tips to safeguard your Mac from the latest malware threats, including the notorious Cthulhu Stealer.
1. Have strong antivirus software: The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe. Get my picks for the best 2024 antivirus protection winners for your Windows, Mac, Android and iOS devices.
2. Be cautious with downloads and links: Only download software from reputable sources such as the Mac App Store or official websites of trusted developers. Be wary of unsolicited emails or messages prompting you to download or install updates, especially if they contain links. Phishing attempts often disguise themselves as legitimate update notifications or urgent messages.
3. Keep your software updated: Ensure that both macOS and all installed applications are up to date. Apple frequently releases security patches and updates that address vulnerabilities. Enable automatic updates for macOS and your apps to stay protected without having to manually check for updates. If you need more help, see my guide on keeping all your devices updated.
4. Use strong and unique passwords: To protect your Mac from malware, it’s also crucial to use strong, unique passwords for all your accounts and devices. Avoid reusing passwords across different sites or services. A password manager can be incredibly helpful here. It generates and stores complex passwords for you, making them difficult for hackers to crack.
It also keeps track of all your passwords in one place and automatically fills them in when you log into accounts, so you don’t have to remember them yourself. By reducing the number of passwords you need to recall, you’re less likely to reuse them, which lowers the risk of security breaches. Get more details about my best expert-reviewed Password Managers of 2024 here.
5. Use Two-Factor Authentication (2FA): Enable 2FA for your important accounts, including your Apple ID, email and any financial services. This adds an extra step to the login process, making it harder for attackers to gain access even if they have your password.
HOW TO REMOVE YOUR PRIVATE DATA FROM THE INTERNET
Kurt’s key takeaway
Macs aren’t as safe from hackers as they used to be. With malware like Cthulhu Stealer and Banshee targeting Mac users, it’s a good reminder to step up your cybersecurity game. These threats can steal your passwords, data and even cryptocurrency, so investing in solid antivirus software and being cautious with what you download is more important than ever.
When downloading new software, how do you determine if it’s safe to install? Do you rely on app store ratings, reviews or something else? Let us know by writing us at Cyberguy.com/Contact
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter
Ask Kurt a question or let us know what stories you’d like us to cover
Follow Kurt on his social channels
Answers to the most asked CyberGuy questions:
New from Kurt:
Copyright 2024 CyberGuy.com. All rights reserved.
Technology
Amazon is ‘winding down’ some of its DEI programs
As we head toward the end of the year, I want to give another update on the work we’ve been doing around representation and inclusion.
As a large, global company that operates in different countries and industries, we serve hundreds of millions of customers from a range of backgrounds and globally diverse communities. To serve them effectively, we need millions of employees and partners that reflect our customers and communities. We strive to be representative of those customers and build a culture that’s inclusive for everyone.
In the last few years we took a new approach, reviewing hundreds of programs across the company, using science to evaluate their effectiveness, impact, and ROI – identifying the ones we believed should continue. Each one of these addresses a specific disparity, and is designed to end when that disparity is eliminated. In parallel, we worked to unify employee groups together under one umbrella, and build programs that are open to all. Rather than have individual groups build programs, we are focusing on programs with proven outcomes – and we also aim to foster a more truly inclusive culture. You can read more about this on our Together at Amazon page on A to Z.
This approach – where we move away from programs that were separate from our existing processes, and instead integrating our work into existing processes so they become durable— is the evolution to “built in” and “born inclusive,” instead of “bolted on.” As part of this evolution, we’ve been winding down outdated programs and materials, and we’re aiming to complete that by the end of 2024. We also know there will always be individuals or teams who continue to do well-intentioned things that don’t align with our company-wide approach, and we might not always see those right away. But we’ll keep at it.
We’ll continue to share ongoing updates, and appreciate your hard work in driving this progress. We believe this is important work, so we’ll keep investing in programs that help us reflect those audiences, help employees grow, thrive, and connect, and we remain dedicated to delivering inclusive experiences for customers, employees, and communities around the world.
Technology
Chinese auto giant wants to make flying cars your next commute option
GAC Group, a prominent automotive manufacturer from China, is making waves in the transportation sector with the launch of its new eVTOL brand, Govy.
This development reflects GAC’s commitment to sustainable air travel, as the company taps into its extensive automotive expertise and innovative technology to create fresh solutions for urban mobility.
With Govy, GAC is not just entering the flying car market; it’s setting the stage for a new era in how we think about commuting and connectivity in our cities.
I’M GIVING AWAY THE LATEST & GREATEST AIRPODS PRO 2
Introducing the AirJet
The flagship aircraft of Govy, named AirJet, is a revolutionary composite-wing flying car designed to operate as an air taxi for distances of up to 124 miles. This innovative vehicle combines the efficiency of fixed-wing aircraft with the flexibility of multi-rotor systems, allowing for vertical takeoff and landing capabilities.
The AirJet is constructed with over 90% carbon fiber composite materials, making it remarkably lightweight — just one-third the weight of a conventional car of similar size. This lightweight design not only enhances performance but also enables longer electric flights.
WHAT IS ARTIFICIAL INTELLIGENCE (AI)?
EVTOL PROTOTYPE PROMISES 150 MPH CITY-TO-CITY HOPS
Performance and features of the AirJet
In terms of performance, the AirJet is powered by GAC’s proprietary electric drive system, which allows it to reach impressive speeds of up to 155 miles per hour. The current model boasts a range exceeding 124 miles, with ambitious plans to extend this range to 249 miles through the development of future solid-state battery technology. Additionally, the AirJet can be recharged in just 30 minutes, ensuring quick turnaround times for operations.
The AirJet is designed with both luxury and safety in mind. It features a spacious cabin with a “1+1+X” seating arrangement that provides flexibility for passengers. The aircraft is equipped with autonomous flight capabilities, allowing for seamless operation without human intervention. Safety is paramount in the design of the AirJet. It includes advanced safety systems such as redundant power and control systems, real-time monitoring, and obstacle detection to ensure secure flights.
AN ELECTRIC AIRCRAFT THE MILITARY HAS ITS EYES ON CAN TAKE OFF WITH ONLY 150 FEET OF RUNWAY
The robo-air taxi system
GAC’s vision extends beyond individual aircraft to encompass a comprehensive Robo-AirTaxi system that integrates ground and aerial transport for end-to-end smart mobility solutions. This system will utilize the Govy AirCar for short urban trips under 12.4 miles and the AirJet for mid-range travel up to 124 miles. A key aspect of this vision is the creation of a “40-minute Greater Bay Area life circle” in China, which aims to facilitate efficient intercity travel and significantly reduce transit times and costs.
THIS FLYING ELECTRIC VEHICLE BREAKS RECORD WITH 523-MILE NONSTOP FLIGHT
Future plans and commercialization
Looking ahead, GAC has outlined an ambitious roadmap for Govy. By 2025, the company aims to achieve airworthiness certification for its flying cars, establish production lines, and begin taking pre-orders from customers. Furthermore, GAC plans to launch demonstration operations in two to three Greater Bay Area cities of China by 2027.
Kurt’s key takeaways
With the introduction of Govy and its flagship AirJet, GAC Group is positioning itself at the forefront of urban aerial transportation. By combining innovative technology with a comprehensive ecosystem approach, GAC aims to transform urban mobility into something smarter, safer, and more sustainable. As we move toward a future where aerial vehicles become an integral part of our transportation networks, GAC’s initiatives could play a pivotal role in shaping how we navigate our cities and connect with one another.
Would you feel comfortable using flying cars like the Govy AirJet for your daily commute, and why or why not? Let us know by writing us at Cyberguy.com/Contact
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter
Ask Kurt a question or let us know what stories you’d like us to cover.
Follow Kurt on his social channels:
Answers to the most asked CyberGuy questions:
New from Kurt:
Copyright 2025 CyberGuy.com. All rights reserved.
Technology
Drone takes out Super Scooper fighting Los Angeles wildfires
An aircraft helping to fight wildfires that are raging across Los Angeles was struck by a civilian drone on Thursday. The collision damaged the wing of the aircraft — a CL-415 “Super Scooper” capable of scooping up 1,600 gallons of ocean water to drop onto nearby blazes — according to a statement by the LA County Fire Department posted on X, putting it out of service until it can be repaired.
Cal Fire spokesman Chris Thomas told The New York Times that grounding the aircraft will likely set back local firefighting efforts. Super Scoopers can typically refill in about five minutes. But even if it takes ten, that’s six water drops that are lost each hour according to Thomas. “So whose house is not going to get that water to protect it?” The Federal Aviation Administration (FAA) says the Super Scooper landed safely after the drone impact, and that the incident is now under investigation.
Temporary flight restrictions have been implemented in the Los Angeles area that prohibit drones and other aircraft from flying without FAA authorization in an effort to protect firefighting efforts.
According to LA County Fire Chief Anthony Marrone, the drone was not assigned to help tackle the Palisades fires, and was destroyed in the collision. Marrone told the LA Times that the FBI is now planning to implement so-called “aerial armor” in the area to prevent further interference from drones.
Several people online have violated the FAA-enforced flight restrictions, posting viral drone photos and video footage across social media showing the devastation from what appears to be prohibited airspace. Fire response agencies are often forced to ground their own aircraft to avoid collisions when dummies fly drones near wildfires for online clout.
“It’s a federal crime, punishable by up to 12 months in prison, to interfere with firefighting efforts on public lands,” the FAA said in a statement. “Additionally, the FAA can impose a civil penalty of up to $75,000 against any drone pilot who interferes with wildfire suppression, law enforcement or emergency response operations. The FAA treats these violations seriously and immediately considers swift enforcement action for these offenses.”
-
Business1 week ago
These are the top 7 issues facing the struggling restaurant industry in 2025
-
Culture1 week ago
The 25 worst losses in college football history, including Baylor’s 2024 entry at Colorado
-
Sports1 week ago
The top out-of-contract players available as free transfers: Kimmich, De Bruyne, Van Dijk…
-
Politics1 week ago
New Orleans attacker had 'remote detonator' for explosives in French Quarter, Biden says
-
Politics1 week ago
Carter's judicial picks reshaped the federal bench across the country
-
Politics6 days ago
Who Are the Recipients of the Presidential Medal of Freedom?
-
Health5 days ago
Ozempic ‘microdosing’ is the new weight-loss trend: Should you try it?
-
World1 week ago
Ivory Coast says French troops to leave country after decades