#GMERA

Malware/Tool

2019-09-20 • Mac Malware that Spoofs Trading App Steals User Information, Uploads it to Website

GMERA is macOS malware distributed through trojanized cryptocurrency and stock-trading applications. Campaigns wrapped legitimate applications or rebranded the Kattana trading application under fictitious names and copied its website, while other samples impersonated Stockfolio. GMERA opens a backdoor, steals information including browser cookies, cryptocurrency wallets, and screen captures, and supports remote terminal access. It reports to a command-and-control server over HTTP and connects reverse-shell sessions to a separate server at a hardcoded IP address. Observed operators used the reverse shell to collect the username, macOS version, and approximate location derived from the victim’s external IP address.

Tagged Reports

« Back