Bitcoin-Stealing OS X Trojan Now Masquerading as 'Angry Birds' and Other Popular Mac Apps

bitcoin.pngA Bitcoin-stealing trojan has been detected in downloads claiming to be cracked versions of popular Mac applications, reports security firm ESET through its We Live Security blog. The OSX/CoinThief.A malware was discovered in popular Bitcoin software earlier this month by SecureMac, but is now being used to target users of more mainstream apps.

The trojan initially surfaced on open source software hosting site GitHub, and it was quickly bundled into several Bitcoin apps available through multiple download sites. Further investigation by ESET has now uncovered the trojan masquerading as cracked versions of popular Mac apps such as BBEdit, Pixelmator, Angry Birds, and Delicious Library.

OSX/CoinThief.A involves a malicious browser add-on used to intercept logins for Bitcoin wallet sites and related exchanges such as MtGox, BTC-e, and blockchain.info. Stolen login credentials are then forwarded to the malware's developer.

There is clearly strong evidence that the trojan was specifically designed to profit from the current Bitcoin craze and fluctuating exchange rates.

According to detection statistics gathered by the ESET LiveGrid, the threat is mostly active amongst Mac users based in the United States.

The websites where these files are being distributed from have not been revealed, but Mac owners can prevent infection by avoiding pirated software and downloading titles directly from the developer's website or the Mac App Store. Users can find instructions on how to check for and remove the malware on SecureMac's blog post.

Top Rated Comments

satcomer Avatar
127 months ago
Pirated software users are surprised that some of these cracked software might be Trojan carriers?
Score: 28 Votes (Like | Disagree)
JetBlack7 Avatar
127 months ago
Joke's on them, I own 0 bitcoins.
Score: 23 Votes (Like | Disagree)
dustinsc Avatar
127 months ago
Downloading cracked apps is like eating out of a garbage bin. Sure, you might find something that looks tasty in there, but even if it looks good it will still probably get you sick.
Score: 22 Votes (Like | Disagree)
tuartboy Avatar
127 months ago
This is why code signing and Gatekeeper exist.
Score: 21 Votes (Like | Disagree)
Plutonius Avatar
127 months ago
Only in cracked versions = no problem.
Score: 18 Votes (Like | Disagree)
WallToWallMacs Avatar
127 months ago
Seems to be a catch22 for Apple. The more successful and ubiquitous it becomes, the more it will be targeted by the nefarious. All the more so because of the statistical affluence of the user base. That's a shame.

How is it a catch 22 for Apple when there are idiots going out to download pirated software because they're too bloody cheap to purchase a legitimate copy via the AppStore? That's like blaming Microsoft for some person downloading Creative Suite off a bittorrenting website then complaining that all their credit card information has been stolen and its apparently all Microsoft's fault.
Score: 16 Votes (Like | Disagree)

Popular Stories

Apple Logo

Apple Discontinued These 5 Products This Year

Monday November 27, 2023 7:03 am PST by
As the end of 2023 nears, now is a good opportunity to look back at some of the devices and accessories that Apple discontinued throughout the year. Apple products discontinued in 2023 include the iPhone 13 mini, 13-inch MacBook Pro, MagSafe Battery Pack, MagSafe Duo Charger, and leather accessories. Also check out our lists of Apple products discontinued in 2022 and 2021. iPhone Mini ...
ios 17 namedrop

Police Departments and News Sites Spreading Misinformation About How iOS 17 NameDrop Feature Works

Monday November 27, 2023 5:11 pm PST by
Apple with iOS 17.1 and watchOS 10.1 introduced a new NameDrop feature that is designed to allow users to place Apple devices near one another to quickly exchange contact information. Sharing contact information is done with explicit user permission, but some news organizations and police departments have been spreading misinformation about how functions. As noted by The Washington Post,...
iOS 17

26 New Things Your iPhone Can Do With Next Month's iOS 17.2 Update

Wednesday November 22, 2023 10:57 pm PST by
Apple made the first beta of iOS 17.2 available to developers in October. Since then we've seen two more betas, and with each iteration Apple continues to add more new features and changes, many of which users have been anticipating for quite a while. Below, we've listed 26 new things that are coming to your iPhone when the finalized version is publicly released in December. 1. Help You...
iOS 17

iOS 17.1.2 Update for iPhone Likely to Be Released This Week

Monday November 27, 2023 8:24 am PST by
Apple will likely release iOS 17.1.2 this week, based on mounting evidence of the software in our website's analytics logs in recent days. As a minor update, iOS 17.1.2 should be focused on bug fixes, but it's unclear exactly which issues might be addressed. Some users have continued to experience Wi-Fi issues on iOS 17.1.1, so perhaps iOS 17.1.2 will include the same fix for Wi-Fi...
Cyber Monday Deals Feature 2022

40+ Apple Cyber Week Deals for AirPods, iPad, Apple Watch, and More

Sunday November 26, 2023 9:47 am PST by
Cyber Week has taken the place of Black Friday, and you'll find some of the same deals still around for the next few days, although many from Black Friday have now expired. This includes dozens of record low prices on Apple products like AirPods, iPad, Apple Watch, MacBook, iPhone, and more. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a...
General Black Friday Deals 2022 Green

40+ Apple Black Friday Deals Still Available for AirPods, iPhone, iPad and More

Friday November 24, 2023 5:01 am PST by
Black Friday 2023 has officially ended, but we're still tracking some of the best deals of the year on Apple products like AirPods, iPad, iPhone, MacBook, and many more. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running. Specifically, in this article we're...