Skip to main content

Threats Tagged 'macos'

View all threats tagged with 'macos'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: macos

Threats Tagged 'macos'

Click on any threat for detailed analysis and mitigation recommendations

An analysis of Atomic macOS (AMOS) stealer infections from early August 2026 reveals this information stealer targeting macOS systems has been advertised since April 2024. AMOS exfiltrates system information, login credentials, and sensitive data from web browsers and cryptocurrency wallets. Distribution methods include ClickFix campaigns, malicious advertisements, and fake cracked software sites offering macOS toolkits. The examined infection chain begins with malicious instructions on getmacouscloud[.]com, leading to execution of a Zsh script that retrieves and installs Mach-O binaries establishing persistence in system directories. The malware collects data from various applications including Binance, TonKeeper, Telegram, AWS, Docker, and FileZilla, compressing it into an out.zip file before exfiltrating to command and control servers. Post-infection traffic consists of HTTP POST requests with specific stage parameters indicating collected data types. The malware demonstrates active development with con...

Join the discussion

This report analyzes the network traffic generated by macOS 27 "Golden Gate" during system boot before user login. It details standard IPv6 neighbor discovery with protections against spoofing, DNS queries for Apple services including device activation and push messaging, and typical TCP connections for certificate validation and push notifications. The system does not advertise services via multicast DNS during boot. No new or unusual network behaviors indicating a security threat were observed.

Join the discussion

Apple released major updates iOS 27 and macOS Golden Gate 27 that patch over 200 security vulnerabilities affecting kernel and multiple platform components. These flaws could lead to memory corruption, privilege escalation, system termination, and information leaks. The updates also fix a medium-severity Samba heap-based buffer overflow from 2022. No active exploitation has been reported. Users are advised to update promptly to benefit from these fixes.

HighVulnerability#macos#ios
Join the discussion

A threat actor compromised the official HBO Max Reddit account and used it to run a malvertising campaign that directed macOS and Windows users to a fake HBO Max site. The site prompted users to execute commands that installed malware designed to steal credentials, messages, browser data, and cryptocurrency wallet information, and maintain persistence. The campaign, active for 48 hours, used multiple malware families including MacSync, AMOS Helper, Amatera Stealer, AnimateClipper, and ZigClipper. Clipboard stealers replaced cryptocurrency addresses to divert transactions. Reddit suspended the malicious ads after notification.

Join the discussion

Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. [...]

Join the discussion

An intrusion was investigated that began with exploitation of CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp RMM software. The threat actor obtained unauthorized technician access and deployed two previously undocumented malware samples: TaskWeaver and Djinn Stealer. TaskWeaver is a heavily obfuscated Node.js loader that establishes encrypted communications and delivers additional payloads. Djinn Stealer targets credentials across Windows, macOS, and Linux systems, collecting authentication data for cloud platforms, source control, package registries, AI development assistants, browsers, SSH keys, and cryptocurrency wallets. The attacker leveraged legitimate RMM capabilities to transfer files and execute commands across managed systems. Stolen AI assistant tokens provided extensive access to repositories, databases, and cloud accounts. The intrusion demonstrated how a single authentication bypass in trusted management infrastructure can enable widespread credential theft and p...

Join the discussion

This content describes a macOS app cleanup feature called App Cleaner integrated into Kaspersky for macOS. It explains how simply deleting an app does not remove all associated files such as caches, settings, and helper services, which can accumulate and consume storage. The feature helps identify and remove these leftover files to free up disk space. The article is informational and does not describe a security vulnerability or threat.

LowAnalysis#macos
Join the discussion

Jamf Threat Labs discovered a cluster of 14 trojanized macOS applications distributed as DMG and PKG files impersonating legitimate software like The Unarchiver, Sketch, and Bartender. These samples are linked to the Contagious Interview campaign, a DPRK-attributed operation using fake job interviews as a pretext. The malware chain begins with unsigned, modified applications containing hidden executables that download staging scripts from infrastructure at 162.0.239[.]85. The attack progresses through multiple stages, ultimately deploying OtterCookie malware, which provides remote access capabilities, credential stealing from browsers and crypto wallets, filesystem scanning, and clipboard monitoring. The delivery method represents an evolution from previous Git hook and VS Code task-based attacks to standalone installer packages requiring manual quarantine attribute removal to execute.

Join the discussion

JSCeal is a sophisticated cryptocurrency-focused stealer malware delivered as compiled V8 bytecode executed by a bundled Node.js runtime. It uses multiple layers of JavaScript obfuscation and compilation to evade analysis. The malware includes capabilities such as keylogging, browser and credential theft, screenshot capture, and HTTPS traffic interception via a local man-in-the-middle proxy. Check Point Research developed a static deobfuscation pipeline to analyze JSCeal without execution, enabling detailed understanding of its behavior and evolution. The malware targets multiple platforms including macOS and continues to evolve with new payload encryption and targeting techniques.

Join the discussion

This macOS malware campaign uses social engineering via fake CAPTCHA pages to trick users into running malicious AppleScript commands. It deploys a persistent backdoor that leverages EtherHiding by storing command-and-control (C2) addresses in Polygon blockchain smart contracts, complicating detection. The malware maintains persistence through LaunchAgents and delivers multiple payloads including the AMOS stealer, which targets cryptocurrency wallets, browser credentials, and macOS Keychain data, as well as the XMRig cryptominer for ongoing revenue. The campaign employs advanced evasion techniques such as character-ID obfuscation and abuse of legitimate macOS utilities. Blockchain transaction analysis reveals the full history of C2 infrastructure rotation and funding, aiding defenders despite the malware's memory-resident nature.

Join the discussion

Showing 1 to 10 of 126 results

Filters:Tag: macos
Page 1 of 13
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses