Hackers posing as tech support are tricking Mac owners into installing malware that raids passwords, cryptocurrency wallets, and business cloud data.
Security researchers have uncovered a sophisticated fraud operation where criminals are calling personal mobile phones and pretending to be legitimate tech support representatives. Once they get someone on the line, they direct victims to visit deceptive websites that mimic real software update alerts. These fake alerts convince users their computers are infected or need urgent updates, prompting them to download what appears to be a helpful tool.
In reality, victims are installing a malicious program written in Go—a programming language often used by developers. This hidden software acts like a digital burglar, systematically searching through the infected Mac computer for valuable information. It specifically targets cryptocurrency wallets where people store digital money, password managers where sensitive login credentials live, Apple's built-in password storage system, and cached login information stored in web browsers.
The criminal group behind this campaign, tracked by researchers as UNC6671, has demonstrated particular interest in stealing access credentials to cloud-based software services—the kind businesses rely on daily for email, file storage, and collaboration tools.
This attack represents a blend of old-school social engineering with modern technical sophistication. Think of it like a con artist who phones you claiming to represent your bank, but instead of just asking for your account number, they're actually installing a hidden camera in your home. The vishing attacks—phone-based fraud—are just the entry point. The real damage happens silently afterward.
The targeting of personal mobile phones is particularly clever. Most people have stronger security awareness when using work computers, but personal devices often lack the same protective oversight. By compromising someone's personal Mac, criminals gain access to their stored passwords and cryptocurrency, which they can then potentially use to infiltrate company systems where the same person works.
The criminals are essentially creating a backdoor into both personal finances and corporate environments through a single deception.
If you use a Mac, store any cryptocurrency, or use cloud services for work, you're in the potential crosshairs. Victims don't just lose personal digital assets—they become unwitting doorways into their employers' networks. A compromised employee account with legitimate access credentials is incredibly valuable to attackers, potentially leading to data breaches affecting thousands of people.
The campaign demonstrates that criminals are evolving beyond traditional phishing emails. They're willing to invest time in phone calls to make their schemes more convincing, which makes them significantly harder to spot than automated mass attacks.
The best defense remains healthy skepticism: if something feels rushed or unusual, it probably is.
Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.
Explore IT Chapters →