Microsoft Discovers macOS Phishing Campaign Targeting Exodus, Ledger, and Trezor Wallets Since Late 2025

According to Microsoft’s security research team, since late 2025, attackers have been distributing fake macOS troubleshooting guides on platforms including Medium, Craft, and Squarespace to trick users into running malicious terminal commands. The commands download and execute malware designed to steal cryptocurrency wallet keys from Exodus, Ledger, and Trezor, along with iCloud data and saved passwords from Chrome and Firefox.

The malware families involved include AMOS, Macsync, and SHub Stealer. In some cases, attackers also delete legitimate wallet applications and replace them with trojanized versions. Apple has added protection in macOS 26.4 to block pasting of potentially malicious commands.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.
Comment
0/400
No comments