A new Mac malware family is masquerading as a legitimate trading app to steal victims’ data and then upload it to a website.

Trend Micro found two samples of the Mac malware family, detected as Trojan.MacOS.GMERA.A, both disguised as the Stockfolio trading app.

The first sample arrived as a .ZIP archive file that contained a copy of the Stockfolio app modified with the attackers’ own digital certificate. When executed, the variant displaced the trading app interface while it performed its malicious functions in the background. These capabilities collected users’ system information, encoded it, saved it in a hidden file and then uploaded it to hxxps://appstockfolio.com/panel/upload[.]php, a domain that was active in January and February.

The researchers used the digital certificate of the first malware sample to detect the second version. That iteration also contained an embedded copy of the Stockfolio app that used the attackers’ digital certificate, and launched the app in a similar way to disguise its malicious intents. Even so, the variant came with a simplified routine and established persistence by creating a property list (plist) file.

A Summer of Mac Malware Campaigns

Trojan.MacOS.GMERA.A isn’t the only Mac malware family that has made headlines in 2019. In June, Malwarebytes detected a threat called Bird Miner that hid within the cracked installer for Ableton Live music production software to infect Mac users with a cryptocurrency miner. Around the same time, Intego spotted malware called CrescentCore posing as Flash Player and using several evasion techniques to avoid detection. Shortly thereafter, Intego observed a threat named NewTab attempting to inject itself into the Safari browser.

How to Defend Against Trojan.MacOS.GMERA.A

Security professionals can help defend against Trojan.MacOS.GMERA.A and similar threats by creating a security awareness training program that educates employees on the tech they’re using and encourages them to download apps only from trusted developers on official app marketplaces. Security leaders should also consider investing in a mobile device management (MDM) solution that applies to internet of things (IoT) products and integrates with existing security tools.

More from

Is It Time to Start Hiding Your Work Emails?

In this digital age, it is increasingly important for businesses to be aware of their online presence and data security. Many companies have already implemented measures such as two-factor authentication and strong password policies – but there is still a great deal of exposure regarding email visibility. It should come as no surprise that cyber criminals are always looking for ways to gain access to sensitive information. Unfortunately, emails are a particularly easy target as many businesses do not encrypt…

2022 Industry Threat Recap: Finance and Insurance

The finance and insurance sector proved a top target for cybersecurity threats in 2022. The IBM Security X-Force Threat Intelligence Index 2023 found this sector ranked as the second most attacked, with 18.9% of X-Force incident response cases. If, as Shakespeare tells us, past is prologue, this sector will likely remain a target in 2023. Finance and insurance ranked as the most attacked sector from 2016 to 2020, with the manufacturing sector the most attacked in 2021 and 2022. What…

X-Force Prevents Zero Day from Going Anywhere

This blog was made possible through contributions from Fred Chidsey and Joseph Lozowski. The 2023 X-Force Threat Intelligence Index shows that vulnerability discovery has rapidly increased year-over-year and according to X-Force’s cumulative vulnerability and exploit database, only 3% of vulnerabilities are associated with a zero day. X-Force often observes zero-day exploitation on Internet-facing systems as a vector for initial access however, X-Force has also observed zero-day attacks leveraged by attackers to accomplish their goals and objectives after initial access was…

And Stay Out! Blocking Backdoor Break-Ins

Backdoor access was the most common threat vector in 2022. According to the 2023 IBM Security X-Force Threat Intelligence Index, 21% of incidents saw the use of backdoors, outpacing perennial compromise favorite ransomware, which came in at just 17%. The good news? In 67% of backdoor attacks, defenders were able to disrupt attacker efforts and lock digital doorways before ransomware payloads were deployed. The not-so-great news? With backdoor access now available at a bargain price on the dark web, businesses…