A fake version of a popular Mac app hides new malware that can steal passwords and crypto wallet keys. Here's how it works.
Warning for Mac users: Cybersecurity experts have discovered a fake app that tricks people into installing dangerous software designed to steal passwords and cryptocurrency.
According to security firm Jamf Threat Labs, criminals created a fake copy of a real, popular Mac app called Maccy (a free tool that manages copied text). People searching online for the app can land on a lookalike website that installs harmful software instead — a type of program called an infostealer (malware built specifically to steal sensitive information).
The malware has been nicknamed PamStealer. What makes it especially sneaky is how it works:
Experts also warn that criminals are now buying sponsored ads on platforms like X (formerly Twitter) and Google to lure people toward these fake apps. Because the ads sometimes come from verified accounts, they look trustworthy.
The bottom line: Only download apps from official sources, be cautious of ads promising free software, and never run commands or scripts you don't fully understand. So far, researchers say this specific malware hasn't been seen actively attacking users, but the threat is real and growing.
This is an AI-generated summary. Read the original article at: https://decrypt.co/372743/fake-mac-clipboard-app-delivers-password-stealing-malware