While Windows devices have long been considered more vulnerable to malware and viruses, macOS functionality has become increasingly commonplace in recent years. With the rapid increase of Mac users, the more popular the operating system is, the more likely it is to become the target of malware attacks. Recently, security research units discovered the emergence of a piece of malware that specifically targets macOS users. Please be vigilant.

Mac users should be careful as new malware is spreading that specifically targets macOS users and steals sensitive data
According to security research unit Check Point Research findings, the new version of Banshee macOS Stealer has begun to spread among the people. Banshee macOS Stealer, a program-as-a-service malware that first came to attention in 2024, could be purchased by any cybercriminal on platforms like Telegram for $3,000, targeting macOS users, security researchers said.

The latest version of the malware was discovered in September 2024. The developers stole the string encryption algorithm from Apple’s XProtect antivirus, allowing it to lie dormant and escape detection by antivirus engines for more than two months. Although the service was eventually shut down after the malware source code was leaked on the dark web, the damage was done while it went undetected. It usually disguises itself as well-known software such as Google Chrome, Telegram and TradingView, and spreads through phishing and GitHub. Once the malware enters the Mac, it will be seamlessly integrated into the system, making detection more difficult. When installed it performs the following actions:
- Steal system data
Browser extensions for browsers like Chrome, Brave, Edge and Vivaldi, as well as cryptocurrency wallets. Leverage two-factor authentication (2FA) extensions to capture sensitive credentials. Additionally, it collects software and hardware details, external IP addresses, and macOS passwords. - deceive users
Use a pop-up window that looks like a system prompt to trick users into entering their macOS password. - evade detection
Leverage anti-analysis techniques to evade testing tools and antivirus engines. - leak data
Stolen information is sent to command and control servers via encrypted and encoded files.

To avoid falling victim to malware in the future, you should take precautions, no matter how safe you think your Mac is. In addition to enabling all of Apple’s various built-in security features, be sure to double-check before you download software from unverified sources. In addition, Apple regularly releases software updates with security patches to address known threats and issues, so please update your Mac operating system to the latest version as much as possible just in case.
Source: KOCPC Chinese