Cybercriminals are using fake Ledger apps to steal seed phrases for cryptocurrency wallets from macOS users. The malware impersonates the genuine app, prompting the user to enter their seed phrase on a phishing site. This technique allows the criminals to empty victims’ wallets. Researchers advise only downloading the Ledger Live app from the official website and only entering the seed phrase when restoring the wallet, directly on the physical Ledger device.

Attack Techniques of Tycoon 2FA Phishing Kit Targeting Microsoft 365 and Gmail Accounts Detailed
The Tycoon 2FA phishing kit has emerged as one of the most sophisticated Phishing-as-a-Service platforms since its debut in August 2023, specifically engineered to circumvent


