Trade Haven Hub - Investing and Stock News
  • Investment Tips
  • Trade Tips
  • Crypto News
  • Economy News
  • Stock Market
  • Investment Tips
  • Trade Tips
  • Crypto News
  • Economy News
  • Stock Market
No Result
View All Result
Trade Haven Hub - Investing and Stock News
No Result
View All Result
Home Crypto News

Fake Ledger Live Apps Target macOS Users in Crypto-Stealing Malware Scam

by
May 23, 2025
in Crypto News
0
Fake Ledger Live Apps Target macOS Users in Crypto-Stealing Malware Scam
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Key Takeaways:

Hackers are targeting macOS users with fake Ledger Live apps to steal seed phrases and crypto funds. Atomic macOS Stealer is the main malware used, found on over 2,800 compromised websites. Moonlock warns that attackers are getting more sophisticated, with multiple active campaigns underway.

A wave of malware attacks targeting macOS users is exploiting trust in Ledger Live, a popular crypto wallet management app.

According to cybersecurity firm Moonlock, hackers are distributing fake versions of the app to steal users’ seed phrases and drain their crypto holdings.

In a report published May 22, Moonlock warned that malicious actors are using trojanized clones of Ledger Live to trick users into entering their recovery phrases through convincing pop-ups.

“Within a year, they have learned to steal seed phrases and empty the wallets of their victims,” the team stated, noting a major evolution in the threat.

Atomic macOS Stealer Emerges as Key Tool in Crypto Theft Campaigns

One of the primary infection vectors is the Atomic macOS Stealer, a tool designed to exfiltrate sensitive data such as passwords, notes, and crypto wallet details.

Moonlock discovered it embedded across at least 2,800 compromised websites.

Once installed, the malware quietly replaces the genuine Ledger Live app with a fake one that triggers fake alerts to harvest seed phrases.

The moment a user enters their 24-word recovery phrase into the phony app, the information is sent to servers controlled by the attacker.

“The fake app then displays a convincing alert about suspicious activity, prompting the user to enter their seed phrase,” Moonlock explained.

“Once entered, the seed phrase is sent to an attacker-controlled server, exposing the user’s assets in seconds.”

Moonlock has been tracking this type of malware since August, identifying at least four ongoing campaigns.

Cybercriminals are compromising websites to spread macOS malware again.

This time: Atomic Stealer hidden in fake password manager installers.

Don’t trust every download. Our latest report explains why.https://t.co/MnL0Sk2A3o#macOS #Malware #Cybersecurity #AtomicStealer

— Moonlock (@moonlock_com) May 20, 2025

While some dark web vendors claim to offer malware with advanced “anti-Ledger” capabilities, Moonlock found that many of these tools are still under development. That hasn’t slowed the attackers, who continue refining their methods.

“This isn’t just a theft,” Moonlock emphasized. “It’s a high-stakes effort to outsmart one of the most trusted tools in the crypto world. And the thieves are not backing down.”

To stay safe, users are urged to avoid downloading apps from unofficial sources, be skeptical of sudden pop-ups asking for a seed phrase, and never share their recovery phrase—no matter how authentic the interface looks.

Microsoft Takes Legal Action Against Lumma Stealer Malware

On May 21, Microsoft took legal and technical action to disrupt Lumma Stealer, a notorious malware operation responsible for widespread information theft, including from crypto wallets.

The company revealed that a federal court in Georgia authorized its Digital Crimes Unit to seize or block nearly 2,300 websites linked to Lumma’s infrastructure.

Working alongside the U.S. Department of Justice, Europol’s European Cybercrime Center, and Japan’s Cybercrime Control Center, Microsoft said it helped dismantle the malware’s command-and-control network and marketplaces where the software was sold to cybercriminals.

Launched in 2022 and continually upgraded, Lumma has been distributed through underground forums and used to harvest passwords, credit card numbers, bank credentials, and digital asset data.

The post Fake Ledger Live Apps Target macOS Users in Crypto-Stealing Malware Scam appeared first on Cryptonews.

Previous Post

Cetus Offers $6M Bounty to Hacker for Return of $56M in Stolen ETH

Next Post

Trump Gifts Tron Founder Justin Sun Golden Watch for Being Top $TRUMP Holder

Next Post
Trump Gifts Tron Founder Justin Sun Golden Watch for Being Top $TRUMP Holder

Trump Gifts Tron Founder Justin Sun Golden Watch for Being Top $TRUMP Holder

  • Trending
  • Comments
  • Latest
Murchison South Increases to 67koz Gold Across Two Pits

Murchison South Increases to 67koz Gold Across Two Pits

May 13, 2025
Bitcoin Records Highest Weekly Close as Price Nears All-Time High

Bitcoin Records Highest Weekly Close as Price Nears All-Time High

May 19, 2025
Major Gold Miners Shine in Q1, Buoyed by Strong Gold Price Performance

Major Gold Miners Shine in Q1, Buoyed by Strong Gold Price Performance

May 14, 2025
Quantum Computing: its Evolution and its Potential Future

Quantum Computing: its Evolution and its Potential Future

March 20, 2025
SPUT’s US$200 Million Uranium Buying Plan Spurs Market Rally

SPUT’s US$200 Million Uranium Buying Plan Spurs Market Rally

0
Quantum Computing: its Evolution and its Potential Future

Quantum Computing: its Evolution and its Potential Future

0
Quantum Computing: its Evolution and its Potential Future

Quantum Computing: its Evolution and its Potential Future

0
Air Direct Capture – Reducing CO2 from the Atmosphere

Air Direct Capture – Reducing CO2 from the Atmosphere

0
SPUT’s US$200 Million Uranium Buying Plan Spurs Market Rally

SPUT’s US$200 Million Uranium Buying Plan Spurs Market Rally

June 18, 2025
Market Presentation

Market Presentation

June 18, 2025
Acquisition of Solar Panel Recycling Technology

Acquisition of Solar Panel Recycling Technology

June 18, 2025
Thune warns Iran should return to negotiating table ‘if they’re smart’

Thune warns Iran should return to negotiating table ‘if they’re smart’

June 18, 2025

    Stay updated with the latest news, exclusive offers, and special promotions. Sign up now and be the first to know! As a member, you'll receive curated content, insider tips, and invitations to exclusive events. Don't miss out on being part of something special.


    By opting in you agree to receive emails from us and our affiliates. Your information is secure and your privacy is protected.

    Recent News

    SPUT’s US$200 Million Uranium Buying Plan Spurs Market Rally

    SPUT’s US$200 Million Uranium Buying Plan Spurs Market Rally

    June 18, 2025
    Market Presentation

    Market Presentation

    June 18, 2025
    Acquisition of Solar Panel Recycling Technology

    Acquisition of Solar Panel Recycling Technology

    June 18, 2025
    Thune warns Iran should return to negotiating table ‘if they’re smart’

    Thune warns Iran should return to negotiating table ‘if they’re smart’

    June 18, 2025
    • About us
    • Contact us
    • Privacy Policy
    • Terms & Conditions

    Copyright © 2025 tradehavenhub.com | All Rights Reserved

    No Result
    View All Result
    • Investment Tips
    • Trade Tips
    • Crypto News
    • Economy News
    • Stock Market

    Copyright © 2025 tradehavenhub.com | All Rights Reserved