Cybercriminals are exploiting counterfeit Ledger Live applications to siphon off cryptocurrency from macOS users via malware that captures seed phrases, according to a cybersecurity firm.
The malware substitutes the authentic Ledger Live app on victims’ devices and subsequently encourages the user to enter their seed phrase through a deceptive pop-up notification, as stated by a team from Moonlock in a report on May 22.
“At first, attackers could utilize the imitation to acquire passwords, notes, and wallet information to gain insight into the wallet’s holdings, but they had no means to withdraw the funds,” the Moonlock team remarked.
