New macOS malware uses Apple’s own code to quietly steal credentials and personal data — how to stay safe

New macOS malware uses Apple’s own code to quietly steal credentials and personal data — how to stay safe New macOS malware uses Apple’s own code to quietly steal credentials and personal data — how to stay safe

While Apple’s Macs aren’t targeted by hackers as often as Windows PCs, they’re far from impenetrable. Security researchers at Check Point Research recently pushed out an alert warning 100 million Apple users that a new variant of the infamous Banshee malware has been detected, capable of stealing browser credentials, cryptocurrency wallets, and other personal data.

Check Point first uncovered the Banshee macOS Stealer, a malware-as-a-service targeting macOS users, in mid-2024, and has been monitoring this latest strain since September. The malware managed to remain undetected for over two months by cleverly incorporating the same encryption methods as Mac’s XProtect antivirus detection suite, with the hackers having “stolen a string encryption algorithm from Apple’s own XProtect antivirus engine, which replaced the plain text strings used in the original version,” Check Point explained. Since antivirus programs expect to see this kind of encryption from Apple’s legitimate security tools, they weren’t flagged as suspicious, allowing the Banshee macOS Stealer to quietly siphon data from targeted devices.

Add a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use