Blog

New macOS malware uses Apple’s own code to quietly steal credentials and personal data — how to stay safe


While Apple’s Macs aren’t targeted by hackers as often as Windows PCs, they’re far from impenetrable. Security researchers at Check Point Research recently pushed out an alert warning 100 million Apple users that a new variant of the infamous Banshee malware has been detected, capable of stealing browser credentials, cryptocurrency wallets, and other personal data.

Check Point first uncovered the Banshee macOS Stealer, a malware-as-a-service targeting macOS users, in mid-2024, and has been monitoring this latest strain since September. The malware managed to remain undetected for over two months by cleverly incorporating the same encryption methods as Mac’s XProtect antivirus detection suite, with the hackers having “stolen a string encryption algorithm from Apple’s own XProtect antivirus engine, which replaced the plain text strings used in the original version,” Check Point explained. Since antivirus programs expect to see this kind of encryption from Apple’s legitimate security tools, they weren’t flagged as suspicious, allowing the Banshee macOS Stealer to quietly siphon data from targeted devices.


Source link

Related Articles

Back to top button
close