Gmera
Aliases: Kassi, StockSteal
- First seen
- 2019-10-01 00:00:00
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Profile updated
- 2026-07-07 14:36:31
Targeted industries: financial-services technology-and-telecommunications
Context
According to PCrisk, GMERA (also known as Kassi trojan) is malicious software that disguises itself as Stockfolio, a legitimate trading app created for Mac users. Research shows that there are two variants of this malware, one detected as Trojan.MacOS.GMERA.A and the other as Trojan.MacOS.GMERA.B. Cyber criminals proliferate GMERA to steal various information and upload it to a website under their control. To avoid damage caused by this malware, remove GMERA immediately.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Osx.Gmera (report)
- Trend Micro — Mac Malware That Spoofs Trading App Steals User Information Uploads It To Website (report)
- objective-see.com — Blog 0X53 (report)
- ESET — Mac Cryptocurrency Trading Application Rebranded Bundled Malware (report)