Gmera

Aliases: Kassi, StockSteal

First seen
2019-10-01 00:00:00
Malware type
trojan, credential-stealer
Family
Malware family
Profile updated
2026-07-07 14:36:31

Targeted industries: financial-services technology-and-telecommunications

Context

According to PCrisk, GMERA (also known as Kassi trojan) is malicious software that disguises itself as Stockfolio, a legitimate trading app created for Mac users. Research shows that there are two variants of this malware, one detected as Trojan.MacOS.GMERA.A and the other as Trojan.MacOS.GMERA.B. Cyber criminals proliferate GMERA to steal various information and upload it to a website under their control. To avoid damage caused by this malware, remove GMERA immediately.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Osx.Gmera (report)
  • Trend Micro — Mac Malware That Spoofs Trading App Steals User Information Uploads It To Website (report)
  • objective-see.com — Blog 0X53 (report)
  • ESET — Mac Cryptocurrency Trading Application Rebranded Bundled Malware (report)

External references