Cybersecurity experts warn of a growing threat to macOS, as the newly discovered Cthulhu Stealer malware exploits Gatekeeper bypass to steal sensitive data
Cybersecurity researchers have identified a new piece of malware designed specifically to target Apple macOS systems, highlighting a growing trend of threat actors setting their sights on the operating system. Named “Cthulhu Stealer,” the malware is available as part of a malware-as-a-service (MaaS) offering, priced at USD 500 per month from late 2023. It is engineered to compromise both x86_64 and Arm architectures.
According to Tara Gould, a researcher from Cado Security, Cthulhu Stealer disguises itself as legitimate software, such as CleanMyMac, Grand Theft Auto IV, or Adobe GenP. The malware is delivered as an Apple disk image (DMG) that contains binaries tailored for different architectures and is written in Golang.
Once a user unwittingly launches the unsigned file and bypasses macOS’s Gatekeeper protections, they are prompted to enter their system password through an osascript-based technique, a method also used by other macOS-focused malware like Atomic Stealer and MacStealer. The malware then prompts for additional credentials, including the user’s MetaMask password, and proceeds to harvest system information, iCloud Keychain passwords, web browser cookies, and Telegram account details. The stolen data is compressed into a ZIP archive and sent to a command-and-control (C2) server controlled by the attackers.
Cthulhu Stealer’s primary goal is to steal credentials and cryptocurrency wallets, particularly targeting game accounts. While the malware shares many similarities with Atomic Stealer, it is not particularly sophisticated, lacking advanced anti-analysis techniques and any standout features that differentiate it from other malware.
The operators behind Cthulhu Stealer are reportedly no longer active, with disputes over payments leading to accusations of an exit scam, ultimately resulting in the main developer being banned from a cybercrime marketplace.
Despite macOS facing fewer threats compared to Windows and Linux, users are advised to exercise caution by downloading software only from trusted sources, avoiding unverified applications, and ensuring their systems are updated with the latest security patches. In response to the rise in macOS malware, Apple has announced new security measures in the upcoming macOS Sequoia, which will prevent users from easily bypassing Gatekeeper protections for unsigned software.

