Hackers have previously developed a special program designed to infect users' devices and steal their cryptocurrencies: Ethereum, Bitcoin, Litecoin. A new version of this program already infects gadgets of users working on macOS. The spread of a malicious program occurs through the application of a zero day of browsers (this expression denotes not an unresolved vulnerability but malicious applications from which there are no protective programs yet).
An improved version of CoinThief is able to infect Mac gadgets with a zero-day JavaScript-related vulnerability in browsers such as Webkit-Chrome, Gecko-Mozilla, Opera, and Safari without customer interaction.
For the first time CoinThief for macOS developers found the antivirus software for SecureMac in February 2014. At that time, this software was distributed through Github, as well as through browsers while downloading information (for example, Download.com, MacUpdate.com).
In November 2017 a new version of the virus was discovered on the symantecblog.com, which is able to monitor the client's clipboard, to identify the user's PC as the target, when the cryptocurrency address is copied regardless of its type.
The company immediately began to check various types of purses, including those which used to save Litecoin, Monero, Ethereum, Namecoin, DASH, and Bitcoin. They found that CoinThief is heavily embedded in the system through qualitatively developed mechanisms and is able to control the wallets with coins equivalent more than $1 000.
The developers of the malicious program were able to steal 214 ETH, 145 BTC, and 21 LTC. The main targets of this software are: representatives of cryptocurrency communities and traders, but the most experts recommend testing for viruses all gadgets and PC on Mac.
It was found that the malicious program use a complex technique called “dylib hijacking”, which is able to embed the virus program in pre-installed applications such as iTunes.