Fake BlueWallet steals passwords, accounts, and crypto from Macs

2026-06-02T08:51:58Z76e0078f8f2f4d4c88a13429954f429b8e40a4081fac77cc6f68389c3b7066ba
chromeclickfixclipboard-theftcredential-theftcrypto-theftdata-breachdeno-ratfake-download-siteghost-cmsmacOSmalwaremfa-bypassmicrosoft-defenderphishingphishing-kitsignal-backup-theftsupply-chainvulnerabilitieswindows

What happened

This Malwarebytes feed highlights multiple active threats and incidents: a fake BlueWallet installer for macOS that steals passwords, crypto wallets, and clipboard data; fake ChatGPT download sites delivering platform-specific malware to Windows and Macs (including Deno RAT distribution via fake GitHub/SourceForge packages); phishing campaigns targeting Signal backup keys and LinkedIn credentials (abusing Adobe Target) and a new Kali365 kit that bypasses MFA to maintain long-term Microsoft account access; a large ClickFix campaign exploiting Ghost CMS to serve malicious Cloudflare-style pages;

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
76e0078f8f2f4d4c88a13429954f429b8e40a4081fac77cc6f68389c3b7066ba
Enrichment time
2026-06-02T08:51:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.