Fake BlueWallet steals passwords, accounts, and crypto from Macs
2026-06-02T08:51:58Z•76e0078f8f2f4d4c88a13429954f429b8e40a4081fac77cc6f68389c3b7066ba
chromeclickfixclipboard-theftcredential-theftcrypto-theftdata-breachdeno-ratfake-download-siteghost-cmsmacOSmalwaremfa-bypassmicrosoft-defenderphishingphishing-kitsignal-backup-theftsupply-chainvulnerabilitieswindows
What happened
This Malwarebytes feed highlights multiple active threats and incidents: a fake BlueWallet installer for macOS that steals passwords, crypto wallets, and clipboard data; fake ChatGPT download sites delivering platform-specific malware to Windows and Macs (including Deno RAT distribution via fake GitHub/SourceForge packages); phishing campaigns targeting Signal backup keys and LinkedIn credentials (abusing Adobe Target) and a new Kali365 kit that bypasses MFA to maintain long-term Microsoft account access; a large ClickFix campaign exploiting Ghost CMS to serve malicious Cloudflare-style pages;
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 76e0078f8f2f4d4c88a13429954f429b8e40a4081fac77cc6f68389c3b7066ba
- Enrichment time
- 2026-06-02T08:51:58Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.