BlockNews
FOLLOW ON X
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • SUI
    • CHAINLINK
    • LITECOIN
  • FINANCE
  • POLITICS
  • MEMECOINS
  • NFT
  • OPINION
No Result
View All Result
BlockNews
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • SUI
    • CHAINLINK
    • LITECOIN
  • FINANCE
  • POLITICS
  • MEMECOINS
  • NFT
  • OPINION
No Result
View All Result
BlockNews
Home CRYPTO

New malware aims to steal Apple users’ crypto via fake blockchain games

BlockNews Team by BlockNews Team
July 28, 2023
in CRYPTO, MEDIA, TECHNOLOGY
Reading Time: 4 mins read
2
SHARES
25
VIEWS
Share on XShare in TelegramShare on Reddit
  • A security research company has reported a new malware distributed through fake blockchain games.
  • As soon as users launch these games and provide passwords, they are soon hit by a malicious code which wipes out their crypto wallet.
  • Because this virus is new and is able to bypass apple’s security system, including yet-to-be-released macOS, security companies are urging users to be extra vigilant.

Security researcher iamdeadlyz has reported on multiple fake blockchain games being used to infect both Windows and macOS with infostealers capable of emptying crypto wallets and stealing personal data such as passwords and emails stored in the browser.

For macOS, the infostealer is a new malware written in Rust, dubbed “Realst”.

Based on this information, security company SentinelOne, reported on its blog post an analysis of these variants of malware, some already targeting macOS 14 Sonoma.

The malware works by attempting to deceive victims through AppleScript spoofing, which involves presenting password request dialogue boxes with hidden answers to capture passwords. Code analysis by SentinelOne found that there is a code from Realst which is a copy of Chainbreaker;  an open-source project that extract passwords, keys and certificates from macOS keychain databases.

According to iamdeadlyz, a malware research company, the malware have a different MacOS build, they are new and so there is no public intel at the moment.

How Realst is distributed

Realst is spread through games including Brawl Earth, Evolion, Pearl, Olymp of Reptiles,  SaintLegend, Wildworld, Destruction and Dawnland.

According to iamdeadlyz, the threat actors approach potential victims through direct messages on social media requesting for those who would like to test a game. Those who fall for it, are soon hit by malware that wipes out their crypto wallet clean. As soon as the victims launch these fake games and provide the installers with passwords, their personal data and crypto funds are stolen.

They give access/refferal codes because the form on the website asks for it in order to download the file. The access code identifies which hacker lured the victim into dowloading the malicious file.

Inside the code, the malware research company was able to figure out some of the activity behind the scene or behind the codes events such as comments in Russian language, Dropbox links and methods to notify the malicious actors

There are instances where download buttons are displayed on the website immediately.

Some versions of malware are distributed by a .pkg installer containing a malicious Mach-O and three related scripts.

Some versions of realst stealer are distributed as application via .dmg disk images. In Some cases, the developer packaged the malware in Electron apps, yet  in others, native macOS application bundles are used.

Realst have the same characteristics as other macOS infostealers, which includes; access and exfiltration of browser data, crypto wallets and keychain databases. With targetted browsers being, Firefox, Chrome, Opera, Brave and Vivaldo. Safari was not targeted in the samples analysted by sentinelOne. However, the malwaware also targets telegram applications.

SentinelONe’s security can detect and prevent all known variants according to Security Analyst from SentinelOne Phil Stokes, there is a need for extra precaution as Apple’s malware blocking service “XProtect” is not able to detect and prevent the execution of malware at the moment.

In addition to anti-malware protection users need to be alert when they encounter blockchain games promising financial rewards, unless they are fully convinced of its legitimacy, they should not download.

Disclaimer: BlockNews provides independent reporting on crypto, blockchain, and digital finance. All content is for informational purposes only and does not constitute financial advice. Readers should do their own research before making investment decisions. Some articles may use AI tools to assist in drafting, but every piece is reviewed and edited by our editorial team of experienced crypto writers and analysts before publication.
Tags: appleblockchain gamesiamdeadlyzmalware
Tweet1ShareShare
BlockNews Team

BlockNews Team

DON'T MISS THESE! HOT OFF THE PRESS

BONK Gears Up for Its First ETP — Here Is Why Whales and Hype Might Finally Trigger a Breakout
CRYPTO

BONK Gears Up for Its First ETP — Here Is Why Whales and Hype Might Finally Trigger a Breakout

November 22, 2025
Uniswap Whales Are Capitulating as UNI Crashes — Here Is Why the Market Looks Fragile and Where Price Might Go Next
CRYPTO

Uniswap Whales Are Capitulating as UNI Crashes — Here Is Why the Market Looks Fragile and Where Price Might Go Next

November 22, 2025
Injective Taps Chainlink Data Streams — Here Is Why This Integration Could Supercharge Its Entire DeFi Ecosystem
CHAINLINK

Injective Taps Chainlink Data Streams — Here Is Why This Integration Could Supercharge Its Entire DeFi Ecosystem

November 22, 2025
Grayscale’s Sui Trust Lands on OTCQX — Here Is Why GSUI Isn’t an ETP Yet (and What Comes Next)
CRYPTO

Grayscale’s Sui Trust Lands on OTCQX — Here Is Why GSUI Isn’t an ETP Yet (and What Comes Next)

November 22, 2025
Cardano Shrugs Off Network Attack With Rapid Recovery — Here Is Why Hoskinson Says the System Proved Its Strength
CARDANO

Cardano Shrugs Off Network Attack With Rapid Recovery — Here Is Why Hoskinson Says the System Proved Its Strength

November 22, 2025
Solana Slides to Its Lowest Level Since June — Here Is Why the Market Looks Fragile and What Happens If SOL Can’t Break $130
CRYPTO

Solana Slides to Its Lowest Level Since June — Here Is Why the Market Looks Fragile and What Happens If SOL Can’t Break $130

November 22, 2025
Load More

Related News

BONK Gears Up for Its First ETP — Here Is Why Whales and Hype Might Finally Trigger a Breakout

BONK Gears Up for Its First ETP — Here Is Why Whales and Hype Might Finally Trigger a Breakout

November 22, 2025
Uniswap Whales Are Capitulating as UNI Crashes — Here Is Why the Market Looks Fragile and Where Price Might Go Next

Uniswap Whales Are Capitulating as UNI Crashes — Here Is Why the Market Looks Fragile and Where Price Might Go Next

November 22, 2025
Injective Taps Chainlink Data Streams — Here Is Why This Integration Could Supercharge Its Entire DeFi Ecosystem

Injective Taps Chainlink Data Streams — Here Is Why This Integration Could Supercharge Its Entire DeFi Ecosystem

November 22, 2025
Grayscale’s Sui Trust Lands on OTCQX — Here Is Why GSUI Isn’t an ETP Yet (and What Comes Next)

Grayscale’s Sui Trust Lands on OTCQX — Here Is Why GSUI Isn’t an ETP Yet (and What Comes Next)

November 22, 2025
Cardano Shrugs Off Network Attack With Rapid Recovery — Here Is Why Hoskinson Says the System Proved Its Strength

Cardano Shrugs Off Network Attack With Rapid Recovery — Here Is Why Hoskinson Says the System Proved Its Strength

November 22, 2025
Twitter Telegram Threads

BLOCKNEWS.COM

BlockNews is your premier source for real-time cryptocurrency, blockchain, political and financial market news.

Stay ahead of the herd with BlockNews

RESOURCES

  • About Us
  • Contact Us
  • Editorial Policies
  • Terms and Conditions
  • Privacy Policy
  • Sitemap

DISCLOSURES AND POLICIES

BlockNews provides independent reporting on crypto, blockchain, and digital finance. Content is for informational purposes only and does not constitute financial advice. Sponsored material is always disclosed. By using this site, you agree to our Terms and Conditions and Privacy Policy.

© 2025 BlockNews

No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • LITECOIN
    • CHAINLINK
    • SUI
  • MEMECOINS
  • POLITICS
  • FINANCE
  • NFT
  • DEFI
  • GUIDES

© 2025 BlockNews