September 23, 2019 By David Bisson 2 min read

A new Mac malware family is masquerading as a legitimate trading app to steal victims’ data and then upload it to a website.

Trend Micro found two samples of the Mac malware family, detected as Trojan.MacOS.GMERA.A, both disguised as the Stockfolio trading app.

The first sample arrived as a .ZIP archive file that contained a copy of the Stockfolio app modified with the attackers’ own digital certificate. When executed, the variant displaced the trading app interface while it performed its malicious functions in the background. These capabilities collected users’ system information, encoded it, saved it in a hidden file and then uploaded it to hxxps://appstockfolio.com/panel/upload[.]php, a domain that was active in January and February.

The researchers used the digital certificate of the first malware sample to detect the second version. That iteration also contained an embedded copy of the Stockfolio app that used the attackers’ digital certificate, and launched the app in a similar way to disguise its malicious intents. Even so, the variant came with a simplified routine and established persistence by creating a property list (plist) file.

A Summer of Mac Malware Campaigns

Trojan.MacOS.GMERA.A isn’t the only Mac malware family that has made headlines in 2019. In June, Malwarebytes detected a threat called Bird Miner that hid within the cracked installer for Ableton Live music production software to infect Mac users with a cryptocurrency miner. Around the same time, Intego spotted malware called CrescentCore posing as Flash Player and using several evasion techniques to avoid detection. Shortly thereafter, Intego observed a threat named NewTab attempting to inject itself into the Safari browser.

How to Defend Against Trojan.MacOS.GMERA.A

Security professionals can help defend against Trojan.MacOS.GMERA.A and similar threats by creating a security awareness training program that educates employees on the tech they’re using and encourages them to download apps only from trusted developers on official app marketplaces. Security leaders should also consider investing in a mobile device management (MDM) solution that applies to internet of things (IoT) products and integrates with existing security tools.

More from

What does resilience in the cyber world look like in 2025 and beyond?

6 min read -  Back in 2021, we ran a series called “A Journey in Organizational Resilience.” These issues of this series remain applicable today and, in many cases, are more important than ever, given the rapid changes of the last few years. But the term "resilience" can be difficult to define, and when we define it, we may limit its scope, missing the big picture.In the age of generative artificial intelligence (gen AI), the prevalence of breach data from infostealers and the near-constant…

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Protecting your digital assets from non-human identity attacks

4 min read - Untethered data accessibility and workflow automation are now foundational elements of most digital infrastructures. With the right applications and protocols in place, businesses no longer need to feel restricted by their lack of manpower or technical capabilities — machines are now filling those gaps.The use of non-human identities (NHIs) to power business-critical applications — especially those used in cloud computing environments or when facilitating service-to-service connections — has opened the doors for seamless operational efficiency. Unfortunately, these doors aren’t the…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today