No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Crypto

New “ModStealer” Malware Targets Crypto Wallets, Evades Antivirus Detection

September 12, 2025
in Crypto
0
New “ModStealer” Malware Targets Crypto Wallets, Evades Antivirus Detection


Key Notes

  • A new malware named “ModStealer” targets crypto wallets across multiple operating systems.
  • It spreads via fake recruiter ads and has remained undetected by major antivirus engines.
  • The malware can steal private keys from 56 different browser wallet extensions.

A new cross-platform malware named “ModStealer” actively targets crypto wallets while remaining undetected by major antivirus software.

The malware is reportedly built to steal sensitive data from users on macOS, Windows, and Linux systems. It has been active for nearly a month before its discovery.


On Sept. 11, first detailed by 9to5Mac, an Apple product-focused publication, in a conversation with the Apple device management firm Mosyle, ModStealer spreads through fake job recruiter ads aimed at developers.

This method is a form of deception similar to sophisticated social engineering scams that have recently resulted in massive crypto user losses.

Beyond crypto wallets, the malware also targets credential files, configuration details, and certificates. It uses a heavily obfuscated JavaScript file written with NodeJS to avoid detection by traditional signature-based security tools.

How ModStealer Operates

The malware establishes persistence on macOS by abusing Apple’s launchctl tool, allowing it to run silently in the background as a LaunchAgent. Data is then sent to a remote server located in Finland but tied to infrastructure in Germany, a method likely used to hide the operator’s actual location.

Mosyle’s analysis found that it targets explicitly 56 different browser wallet extensions, including those on Safari, to extract private keys, highlighting the importance of using secure decentralized crypto wallets.

The malware can also capture clipboard data, take screenshots, and execute remote code, giving attackers near-total control over an infected device.

This discovery follows other recent security breaches in the crypto ecosystem. Earlier this week, a widespread NPM supply chain attack attempted to compromise developers using spoofed emails to steal credentials.

That attack aimed to hijack transactions across multiple chains, including Ethereum

ETH
$4 542



24h volatility:
2.7%


Market cap:
$547.26 B



Vol. 24h:
$29.19 B



and Solana

SOL
$239.0



24h volatility:
5.6%


Market cap:
$129.59 B



Vol. 24h:
$12.79 B



, by swapping crypto addresses.

However, it was largely contained, with attackers stealing only about $1,000, a minor sum compared to other major crypto heists where hackers have successfully laundered and reinvested millions in stolen assets.

Researchers at Mosyle believe ModStealer fits the profile of a “Malware-as-a-Service” (MaaS) operation. This model, increasingly popular with cybercriminals, involves selling ready-made malware to affiliates who may have minimal technical skills.

Mosyle stated the threat is a reminder that signature-based protections alone are not enough and that behaviour-based defences are necessary to stay ahead of new attack vectors.

next

Disclaimer: Coinspeaker is committed to providing unbiased and transparent reporting. This article aims to deliver accurate and timely information but should not be taken as financial or investment advice. Since market conditions can change rapidly, we encourage you to verify information on your own and consult with a professional before making any decisions based on this content.

Cryptocurrency News, News


As a Web3 marketing strategist and former CMO of DuckDAO, Zoran Spirkovski translates complex crypto concepts into compelling narratives that drive growth. With a background in crypto journalism, he excels in developing go-to-market strategies for DeFi, L2, and GameFi projects.

Zoran Spirkovski on X


Editorial Team

Editorial Team

Related Posts

Vader launches EgoPlay closed beta for gamified smart glasses tasks
Crypto

Vader launches EgoPlay closed beta for gamified smart glasses tasks

September 12, 2025
inflation-us-vs-xrp-explosion-cours
Crypto

Inflation US vs XRP : vers une explosion du cours ?

September 12, 2025
Small Crypto Trader Turns $6.8K Into $1.5M With High-Risk Strategy
Crypto

Small Crypto Trader Turns $6.8K Into $1.5M With High-Risk Strategy

September 12, 2025
DTCC lists Solana, XRP, and Hedera ETFs as SEC verdicts near
Crypto

DTCC lists Solana, XRP, and Hedera ETFs as SEC verdicts near

September 12, 2025
Micron stock hits all-time high
Crypto

Micron stock hits all-time high

September 12, 2025
Dogecoin Leads Crypto Gainers as Bloomberg Analyst Confirm Rex-Osprey DOGE ETF Launch Date
Crypto

Dogecoin Leads Crypto Gainers as Bloomberg Analyst Confirm Rex-Osprey DOGE ETF Launch Date

September 12, 2025
Load More
Next Post
Weekend Essay: Angela Rayner and the price of not seeking advice

Weekend Essay: Angela Rayner and the price of not seeking advice

Popular News

  • Josh Garber

    How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Guide to Emirates Cancellation Policy

    0 shares
    Share 0 Tweet 0
  • Exclusive-Gunvor expands precious metals business into physical trading

    0 shares
    Share 0 Tweet 0
  • SMALL CAP MOVERS: Lupus drug patent lights up the market

    0 shares
    Share 0 Tweet 0

Latest News

Vader launches EgoPlay closed beta for gamified smart glasses tasks

Vader launches EgoPlay closed beta for gamified smart glasses tasks

September 12, 2025
0

Key Takeaways Vader launched EgoPlay, a gamified platform for task completion using smart glasses. EgoPlay users earn Vader Points for...

Interview: Listen to Octopus boss Greg Jackson discuss how we can bring bills down

Interview: Listen to Octopus boss Greg Jackson discuss how we can bring bills down

September 12, 2025
0

By THIS IS MONEY Updated: 12:28 EDT, 12 September 2025 --> --> --> As the founder and CEO of Octopus...

Transit tech firm Via valued at $3.5 billion as shares fall in NYSE debut

Transit tech firm Via valued at $3.5 billion as shares fall in NYSE debut

September 12, 2025
0

Transit tech firm Via valued at $3.5 billion as shares fall in NYSE debut

11 Best Airbnbs in Orlando for Disney Weekends and Winter Sun

11 Best Airbnbs in Orlando for Disney Weekends and Winter Sun

September 12, 2025
0

When you think of Orlando, visions of Disney World, Universal Studios, sunshine, and palm trees will likely pop into your...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.