Close Menu
Cryphedge.com
  • Home
  • Crypto News
    • Bitcoin
    • NFT News
  • Altcoins
  • Scams
  • Blockchain
  • Regulations
  • Trading
Facebook X (Twitter) Instagram
Cryphedge.com
  • Home
  • Crypto News
    • Bitcoin
    • NFT News
  • Altcoins
  • Scams
  • Blockchain
  • Regulations
  • Trading
Cryphedge.com
Home » Fake Ledger Live Apps Target macOS Users
Fake Ledger Live Apps Target macOS Users

Fake Ledger Live Apps Target macOS Users

May 23, 20254 Mins ReadNo Comments Crypto News
Share
Facebook Twitter LinkedIn Pinterest Email

Crypto Journalist

Amin Ayan

Fake Ledger Live Apps Target macOS Users

Crypto Journalist

Amin Ayan

About Author

Amin Ayan is a crypto journalist with over four years of experience in the industry. He has contributed to leading publications such as Cryptonews, Investing.com, 99Bitcoins, and 24/7 Wall St. He has…

Share

Last updated: 

May 22, 2025


Why Trust Cryptonews

Cryptonews has covered the cryptocurrency industry topics since 2017, aiming to provide informative insights to our readers. Our journalists and analysts have extensive experience in market analysis and blockchain technologies. We strive to maintain high editorial standards, focusing on factual accuracy and balanced reporting across all areas – from cryptocurrencies and blockchain projects to industry events, products, and technological developments. Our ongoing presence in the industry reflects our commitment to delivering relevant information in the evolving world of digital assets. Read more about Cryptonews

Fake Ledger Live Apps Target macOS Users in Crypto-Stealing Malware Scam

Key Takeaways:

  • Hackers are targeting macOS users with fake Ledger Live apps to steal seed phrases and crypto funds.
  • Atomic macOS Stealer is the main malware used, found on over 2,800 compromised websites.
  • Moonlock warns that attackers are getting more sophisticated, with multiple active campaigns underway.

A wave of malware attacks targeting macOS users is exploiting trust in Ledger Live, a popular crypto wallet management app.

According to cybersecurity firm Moonlock, hackers are distributing fake versions of the app to steal users’ seed phrases and drain their crypto holdings.

In a report published May 22, Moonlock warned that malicious actors are using trojanized clones of Ledger Live to trick users into entering their recovery phrases through convincing pop-ups.

“Within a year, they have learned to steal seed phrases and empty the wallets of their victims,” the team stated, noting a major evolution in the threat.

Atomic macOS Stealer Emerges as Key Tool in Crypto Theft Campaigns

One of the primary infection vectors is the Atomic macOS Stealer, a tool designed to exfiltrate sensitive data such as passwords, notes, and crypto wallet details.

Moonlock discovered it embedded across at least 2,800 compromised websites.

Once installed, the malware quietly replaces the genuine Ledger Live app with a fake one that triggers fake alerts to harvest seed phrases.

The moment a user enters their 24-word recovery phrase into the phony app, the information is sent to servers controlled by the attacker.

“The fake app then displays a convincing alert about suspicious activity, prompting the user to enter their seed phrase,” Moonlock explained.

“Once entered, the seed phrase is sent to an attacker-controlled server, exposing the user’s assets in seconds.”

Moonlock has been tracking this type of malware since August, identifying at least four ongoing campaigns.

While some dark web vendors claim to offer malware with advanced “anti-Ledger” capabilities, Moonlock found that many of these tools are still under development. That hasn’t slowed the attackers, who continue refining their methods.

“This isn’t just a theft,” Moonlock emphasized. “It’s a high-stakes effort to outsmart one of the most trusted tools in the crypto world. And the thieves are not backing down.”

To stay safe, users are urged to avoid downloading apps from unofficial sources, be skeptical of sudden pop-ups asking for a seed phrase, and never share their recovery phrase—no matter how authentic the interface looks.

Microsoft Takes Legal Action Against Lumma Stealer Malware

On May 21, Microsoft took legal and technical action to disrupt Lumma Stealer, a notorious malware operation responsible for widespread information theft, including from crypto wallets.

The company revealed that a federal court in Georgia authorized its Digital Crimes Unit to seize or block nearly 2,300 websites linked to Lumma’s infrastructure.

Working alongside the U.S. Department of Justice, Europol’s European Cybercrime Center, and Japan’s Cybercrime Control Center, Microsoft said it helped dismantle the malware’s command-and-control network and marketplaces where the software was sold to cybercriminals.

Launched in 2022 and continually upgraded, Lumma has been distributed through underground forums and used to harvest passwords, credit card numbers, bank credentials, and digital asset data.


Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
cryphedge

Related Posts

4 Top Projects Built for Speed, Scale, and Utility – Crypto News Flash

June 13, 2025

Tony G Expands Crypto Portfolio, Invests $438K in Hyperliquid

June 13, 2025

Building a Portfolio for Q3: Why Combining Chainlink (LINK) and POL (ex-MATIC) Could Be a Winning Strategy

June 12, 2025

Pi Network Gains 15%, UNI Adds 28%, But BlockDAG’s $298M Presale Stands Out in 2025

June 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

SEC pulls back from crypto rules proposed under Gary Gensler administration

June 13, 2025

Can 20 Trillion Yearly Burns Drive SHIB To $0.001?

June 13, 2025

BinanceCoin (BNB) & Uniswap (UNI) Attract Significant Gains- Will They Revive a Notable Recovery?

June 13, 2025

How Nemo Money Is Redefining Global Investing With Smart Tools and Zero Commission Trading

June 13, 2025
About

cryphedge is an online news portal that aims to share the latest crypto news, bitcoin, altcoin, blockchain, nft news, regulation, trading, crypto scams and much more stuff.

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

How Long Until You Can Turn $1000 in PI Into $1 Million?

May 8, 2025

Bitcoin eyes $112k as Strategy announces plans to buy $2.1B BTC

May 22, 2025

$2.38 Support Holds As Chart Data Signals $15 Target

May 14, 2025
Subscribe
Please enable JavaScript in your browser to complete this form.
Loading
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Use
  • DMCA

Type above and press Enter to search. Press Esc to cancel.

  • bitcoinBitcoin(BTC)$105,095.00-1.75%
  • ethereumEthereum(ETH)$2,552.13-6.27%
  • tetherTether(USDT)$1.000.03%
  • rippleXRP(XRP)$2.16-3.18%
  • binancecoinBNB(BNB)$653.39-1.35%
  • solanaSolana(SOL)$145.72-7.82%
  • usd-coinUSDC(USDC)$1.000.00%
  • dogecoinDogecoin(DOGE)$0.175683-6.28%
  • tronTRON(TRX)$0.2735200.62%
  • staked-etherLido Staked Ether(STETH)$2,552.12-6.29%
  • cardanoCardano(ADA)$0.64-5.57%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$105,031.00-1.83%
  • HyperliquidHyperliquid(HYPE)$40.30-0.90%
  • Wrapped stETHWrapped stETH(WSTETH)$3,078.85-6.13%
  • suiSui(SUI)$3.03-7.12%
  • chainlinkChainlink(LINK)$13.36-5.55%
  • leo-tokenLEO Token(LEO)$9.072.27%
  • bitcoin-cashBitcoin Cash(BCH)$419.19-2.01%
  • avalanche-2Avalanche(AVAX)$19.27-7.79%
  • stellarStellar(XLM)$0.260266-4.91%
  • the-open-networkToncoin(TON)$2.98-5.73%
  • USDSUSDS(USDS)$1.00-0.01%
  • shiba-inuShiba Inu(SHIB)$0.000012-6.08%
  • WETHWETH(WETH)$2,552.63-6.33%
  • Wrapped eETHWrapped eETH(WEETH)$2,731.08-6.22%
  • hedera-hashgraphHedera(HBAR)$0.155154-7.24%
  • litecoinLitecoin(LTC)$84.25-4.80%
  • Binance Bridged USDT (BNB Smart Chain)Binance Bridged USDT (BNB Smart Chain)(BSC-USD)$1.000.07%
  • Ethena USDeEthena USDe(USDE)$1.00-0.07%
  • polkadotPolkadot(DOT)$3.84-4.48%
  • moneroMonero(XMR)$312.11-3.29%
  • bitget-tokenBitget Token(BGB)$4.53-3.50%
  • whitebitWhiteBIT Coin(WBT)$34.404.98%
  • Coinbase Wrapped BTCCoinbase Wrapped BTC(CBBTC)$105,044.00-1.82%
  • pepePepe(PEPE)$0.000011-11.18%
  • uniswapUniswap(UNI)$7.33-6.08%
  • aaveAave(AAVE)$283.53-3.15%
  • Pi NetworkPi Network(PI)$0.56-11.05%
  • daiDai(DAI)$1.000.05%
  • Ethena Staked USDeEthena Staked USDe(SUSDE)$1.18-0.02%
  • BittensorBittensor(TAO)$368.90-6.06%
  • okbOKB(OKB)$51.88-2.32%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • internet-computerInternet Computer(ICP)$5.43-7.88%
  • aptosAptos(APT)$4.44-8.80%
  • nearNEAR Protocol(NEAR)$2.24-8.67%
  • crypto-com-chainCronos(CRO)$0.091430-5.95%
  • ethereum-classicEthereum Classic(ETC)$16.47-5.91%
  • sUSDSsUSDS(SUSDS)$1.060.01%
  • Jito Staked SOLJito Staked SOL(JITOSOL)$175.95-7.88%
  • OndoOndo(ONDO)$0.78-6.41%
  • Tokenize XchangeTokenize Xchange(TKX)$28.89-6.37%
  • Lombard Staked BTCLombard Staked BTC(LBTC)$105,736.00-1.02%
  • USD1USD1(USD1)$1.000.02%
  • mantleMantle(MNT)$0.64-2.89%
  • gatechain-tokenGate(GT)$17.07-3.27%
  • kaspaKaspa(KAS)$0.078330-7.04%
  • Official TrumpOfficial Trump(TRUMP)$9.93-3.27%
  • vechainVeChain(VET)$0.022401-7.03%
  • fasttokenFasttoken(FTN)$4.44-0.13%
  • cosmosCosmos Hub(ATOM)$4.10-5.91%
  • polygon-ecosystem-tokenPOL (ex-MATIC)(POL)$0.202029-7.35%
  • EthenaEthena(ENA)$0.294474-10.46%
  • render-tokenRender(RENDER)$3.41-7.65%
  • fetch-aiArtificial Superintelligence Alliance(FET)$0.66-9.43%
  • SkySky(SKY)$0.079203-4.59%
  • arbitrumArbitrum(ARB)$0.340535-10.13%
  • filecoinFilecoin(FIL)$2.39-7.68%
  • worldcoin-wldWorldcoin(WLD)$0.98-9.34%
  • quant-networkQuant(QNT)$107.34-6.51%
  • Binance-Peg WETHBinance-Peg WETH(WETH)$2,556.31-6.27%
  • algorandAlgorand(ALGO)$0.176650-7.50%
  • first-digital-usdFirst Digital USD(FDUSD)$1.000.06%
  • Jupiter Perpetuals Liquidity Provider TokenJupiter Perpetuals Liquidity Provider Token(JLP)$4.37-3.40%
  • USDT0USDT0(USDT0)$1.000.08%
  • USDtbUSDtb(USDTB)$1.00-0.01%
  • kucoin-sharesKuCoin(KCS)$11.24-0.74%
  • Binance Staked SOLBinance Staked SOL(BNSOL)$153.99-7.68%
  • SPX6900SPX6900(SPX)$1.32-20.68%
  • flare-networksFlare(FLR)$0.017983-3.06%
  • nexoNEXO(NEXO)$1.21-2.81%
  • rocket-pool-ethRocket Pool ETH(RETH)$2,906.33-6.19%
  • Virtuals ProtocolVirtuals Protocol(VIRTUAL)$1.84-11.93%
  • JupiterJupiter(JUP)$0.405033-10.85%
  • CelestiaCelestia(TIA)$1.77-13.38%
  • Kelp DAO Restaked ETHKelp DAO Restaked ETH(RSETH)$2,671.17-6.30%
  • injective-protocolInjective(INJ)$11.56-9.42%
  • bonkBonk(BONK)$0.000014-10.69%
  • FartcoinFartcoin(FARTCOIN)$1.10-16.43%
  • SonicSonic(S)$0.324871-10.69%
  • StoryStory(IP)$3.52-10.44%
  • optimismOptimism(OP)$0.59-12.02%
  • Binance Bridged USDC (BNB Smart Chain)Binance Bridged USDC (BNB Smart Chain)(USDC)$1.000.15%
  • Polygon Bridged USDT (Polygon)Polygon Bridged USDT (Polygon)(USDT)$1.000.02%
  • paypal-usdPayPal USD(PYUSD)$1.00-0.05%
  • xdce-crowd-saleXDC Network(XDC)$0.060370-5.68%
  • Mantle Staked EtherMantle Staked Ether(METH)$2,729.61-6.46%
  • blockstackStacks(STX)$0.62-6.87%
  • sei-networkSei(SEI)$0.175633-7.51%
  • StakeWise Staked ETHStakeWise Staked ETH(OSETH)$2,674.42-6.29%