ModStealer malware targets crypto wallets on Windows, macOS, and Linux, stealing keys and data. Read how it spreads and how to stay safe.   ModStealer malware is becoming one of the most pressing threats to crypto wallets.  Security researchers discovered that it can now infiltrate systems running Windows, macOS and Linux. Once installed, it extracts […] The post Crypto Researchers Find Another Undetectable Cross-Platform Wallet Drainer appeared first on Live Bitcoin News.ModStealer malware targets crypto wallets on Windows, macOS, and Linux, stealing keys and data. Read how it spreads and how to stay safe.   ModStealer malware is becoming one of the most pressing threats to crypto wallets.  Security researchers discovered that it can now infiltrate systems running Windows, macOS and Linux. Once installed, it extracts […] The post Crypto Researchers Find Another Undetectable Cross-Platform Wallet Drainer appeared first on Live Bitcoin News.

Crypto Researchers Find Another Undetectable Cross-Platform Wallet Drainer

2025/09/13 15:30
3 min read

ModStealer malware targets crypto wallets on Windows, macOS, and Linux, stealing keys and data. Read how it spreads and how to stay safe.

 

ModStealer malware is becoming one of the most pressing threats to crypto wallets. 

Security researchers discovered that it can now infiltrate systems running Windows, macOS and Linux. Once installed, it extracts sensitive information including wallet credentials, private keys and certificates.

The malware was uncovered by Apple-focused security firm Mosyle. According to their findings, ModStealer avoided detection by most antivirus engines for nearly a month after being uploaded to VirusTotal. 

How ModStealer Operates

Mosyle revealed that ModStealer is a feature-rich infostealer. It comes loaded with code designed to harvest sensitive data from browser-based wallet extensions. 

Targets include popular extensions on Safari and Chromium-based browsers.

On macOS systems, the malware gains persistence by using Apple’s launchctl tool. 

It registers itself as a background agent and silently monitors activity. On all operating systems, it can capture clipboard data, take screenshots and even execute remote commands.

Researchers traced the malware’s server to Finland, even though the infrastructure appears to be routed through Germany.

Fake Job Ads Fuel Malware Distribution

The malware is spreading through fake job recruitment ads. Cybercriminals disguise themselves as recruiters offering technical assessments or test tasks. 

Developers who download these files unknowingly install ModStealer and give attackers access to sensitive data.

This tactic has become increasingly common in Web3 communities. Hacken’s Stephen Ajayi, a technical lead in blockchain security, warned that fake test assignments are now a standard tool for attackers.

He advised handling assignments only in disposable virtual machines that contain no wallets, SSH keys, or password managers.

Advice From Security Experts

Ajayi stressed that users must separate their work and wallet environments. He recommended using a “dev box” for development and a “wallet box” for storing digital assets. 

This compartmentalisation reduces the chance of wallet compromise.

He also pointed out the importance of wallet hygiene. Hardware wallets, offline storage of seed phrases and careful confirmation of wallet addresses are all great strategies for reducing exposure.

Malware-as-a-Service Adds Scale

Researchers believe ModStealer is part of a growing Malware-as-a-Service (MaaS) market. 

Criminals package malware for resale to affiliates, who can then deploy it without technical expertise. This model allows for quick scaling of attacks.

Mosyle noted that ModStealer reflects a wider trend in Mac malware. Infostealers now dominate threats targeting Apple systems, with Jamf reporting a 28% rise this year.

Wider Threats to Crypto Users

The risks extend beyond ModStealer. A recent case pointed out how phishing remains one of the most damaging attack methods. 

Blockchain analytics firm Lookonchain reported that an investor lost $3.05 million in Tether (USDT) after unknowingly approving a malicious transaction.

The investor only checked the first and last few characters of a wallet address. Attackers exploited that habit to redirect funds.

According to security firm CertiK, crypto users lost more than $2.2 billion to hacks, scams, and breaches in the first half of the year. 

Wallet hacks alone accounted for $1.7 billion across just 34 incidents. Phishing scams added over $410 million across 132 attacks.

 

Market Opportunity
CROSS Logo
CROSS Price(CROSS)
$0.10359
$0.10359$0.10359
-0.82%
USD
CROSS (CROSS) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

XRP Confirms Downtrend After $1.50 Breakdown, with $1.15 in Focus

XRP Confirms Downtrend After $1.50 Breakdown, with $1.15 in Focus

XRP price is currently trading near $1.44 on Sunday, February 8, after dipping to $1.21 earlier in the week. The price has been declining from its high near $1.
Share
Tronweekly2026/02/08 21:17
Will Bitcoin Crash Again After Trump Insider Whale Dumps 6,599 BTC?

Will Bitcoin Crash Again After Trump Insider Whale Dumps 6,599 BTC?

Trump insider Garrett Jin moves 6,599 BTC to Binance, raising concerns about more Bitcoin sell pressure as market sentiment weakens. Bitcoin has seen a turbulent
Share
LiveBitcoinNews2026/02/08 21:30
China’s Ban on Nvidia Chips for State Firms Sends Stock Tumbling

China’s Ban on Nvidia Chips for State Firms Sends Stock Tumbling

The post China’s Ban on Nvidia Chips for State Firms Sends Stock Tumbling appeared on BitcoinEthereumNews.com. Cyberspace Administration of China (CAC) has instructed big companies to stop purchasing and cancel existing orders for Nvidia’s RTX Pro 6000D chip The ban is part of China’s ongoing effort to reduce dependency on US-made AI hardware, especially after restrictive US export rules After the news, Nvidia shares dropped in premarket trading by about 1.5% Cyberspace Administration of China (CAC) has instructed big companies like Alibaba and ByteDance to stop purchasing and cancel existing orders for Nvidia’s RTX Pro 6000D chip. The ban is part of China’s ongoing effort to reduce dependency on US-made AI hardware, especially after restrictive US export rules. The RTX Pro 6000D was tailored for China to comply with some export rules, but now the regulator says even that chip is off-limits. After the news, Nvidia shares dropped in premarket trading (around 1.5%), reflecting investors’ concerns about reduced demand in one of the biggest markets. This isn’t the first time China has done something like this. For instance, in August, the country urged firms not to use Nvidia’s H20 chip due to potential security issues and the need to comply with international export control regulations. Meanwhile, Alibaba and Baidu have begun using domestically produced AI chips more heavily, which shows that China is seriously investing in building its own chip-making capacity. Additionally, a few days ago, Chinese regulators opened an antitrust review into Nvidia’s Mellanox acquisition, suggesting the company may have broken some of the promises it made to get the 2020 deal passed. From AI to blockchain and the possible effects of China’s ban The banning of Nvidia chips represents a rather notable escalation in the technological rivalry between the United States and China. Beyond tariffs or export bans, China is now proactively telling its firms to avoid even “compliant” US chips and instead shift…
Share
BitcoinEthereumNews2025/09/18 07:46