Skip to main content
  1. Home
  2. Computing
  3. News

This new threat proves that Macs aren’t immune from malware

Add as a preferred source on Google
A hacker typing on an Apple MacBook laptop while holding a phone. Both devices show code on their screens.
Sora Shimazaki / Pexels

Despite constant warnings, many Mac users have come to believe their computers are safe from malware attacks. A new threat targeting Mac users called Banshee Stealer, however, refutes that notion. As reported on by security firm Elastic Labs, Banshee Stealer targets popular browsers and crypto wallets and even attempts to steal data from iCloud Keychain passwords and Notes.

“Banshee Stealer targets a wide range of browsers, cryptocurrency wallets, and around 100 browser extensions, making it a highly versatile and dangerous threat,” Elastic Security Labs said in a report on Thursday.

Recommended Videos

The new malware collects browser history, cookies, logins, and more, all from some of the most popular browsers and crypto wallets, including Microsoft Edge, Google Chrome, Mozilla Firefox, Electrum, Coinomi, Wasabi Wallet, and more.

Banshee Stealer incorporates measures to make it difficult for security researchers to find flaws in it or understand how it works. An interesting detail is that it uses the CFLocaleCopyPreferredLanguages API to detect the computer’s primary language. If the user sets the language to Russian, it avoids infecting the system.

However, the malware can also show users a fake password prompt to try to trick the user into entering their password to gain privilege escalation. After launching an app, the user will see a prompt and a message telling them to update system settings and to enter their password.

It can also grab info from files matching a number of different file formats, including .txt, .docx, .wallet, and more.

Broadcom-owned Symantec explained how it works in more detail: “It begins by running a Swift-based dropper that displays a fake password prompt to deceive users. After capturing credentials, the malware verifies them using the OpenDirectory API and subsequently downloads and executes malicious scripts from a command-and-control server.”

Like other malware, the Banshee Stealer is being sold, but the unusual thing is its hefty $3,000 a month price. Elastic Labs notes that this is quite a high price, especially compared to similar Windows malware.

This malware threat isn’t the first and won’t be the last. However, Mac users can take precautions to stay safe, such as being cautious about where they download files and always keeping their Mac updated since it contains critical security patches. And hey, some antivirus software isn’t a terrible idea either.

Judy Sanhz
Computing Writer
Judy Sanhz is a Digital Trends computing writer covering all computing news. Loves all operating systems and devices.
A simple coding mistake is exposing API keys across thousands of websites
Security gaps that are easier to miss than you think
Computer, Electronics, Laptop

After analyzing 10 million webpages, researchers have found thousands of websites accidentally exposing sensitive API credentials, including keys linked to major services like Amazon Web Services, Stripe, and OpenAI.

This is a serious issue because APIs act as the backbone of the apps we use today. They allow websites to connect to services like payments, cloud storage, and AI tools, but they rely on digital keys to stay secure. Once exposed, API keys can allow anyone to interact with those services with malicious intent.

Read more
AMD’s latest Ryzen 9 9950X3D2 pushes X3D to the limit
Dual 3D V-Cache, higher power, and a focus on enthusiast performance
AMD Ryzen 9 9950X3D2 FEatured

AMD has unveiled what might be its most extreme desktop CPU yet, the Ryzen 9 9950X3D2. And it’s going all-in on one thing: cache.

https://twitter.com/jackhuynh/status/2037159705395491033?s=20

Read more
Next-gen AI breakthrough promises chatbots that can read the room better
Researchers are teaching AI chatbots to read between the lines
Generative AI

Have you ever asked a chatbot something and felt like it completely missed your point? You say something with a bit of nuance, and the AI misses the subtlety entirely. That is exactly the problem researchers are trying to solve.

Even though the emotional connection with AI can feel deeper than human conversation for many users, most AI systems today still treat a sentence as a single block of sentiment. If you mix praise and criticism, the nuance often gets lost.

Read more