A multicomponent malicious program designed to steal Bitcoin electronic currency from computers running OS X. The malware is disguised as a legitimate mining application (for example, BitVanity, StealthBit, Bitcoin Ticker TTM, Litecoin Ticker).
It consists of the following components:
- An installer distributed in the guise of a legitimate application.
- An agent that performs a variety of tasks (for example, it can process intercepted data, check applications installed on the system, and update itself).
It uses the following path for the installation:
~/Library/Application Support/.com.google.softwareUpdateAgent
- A browser extension called Pop-Up Blocker that filters traffic, performs the functions of the agent, and communicates with the command and control server.
The Trojan’s main objective is to monitor traffic and steal private data stored by Bitcoin and Litecoin mining applications. Also, if Bitcoin-Qt is installed on the infected computer, Trojan.CoinThief modifies the program and steals the private data stored by the application.