Skip to main content
  1. Home
  2. Computing
  3. News

Is macOS more secure than Windows? This malware report has the answer

Add as a preferred source on Google

It’s a long-held belief that Macs are less at risk of malware and viruses than Windows PCs, but how true is that? Well, a new report has shed some light on the situation — and the results might surprise you.

According to threat research firm Elastic Security Labs, roughly 39% of all malware infections happen on Windows PCs. In good news for Apple fans, only 6% of breaches occurred on macOS, making Mac systems far less vulnerable than their Windows counterparts.

A person using a laptop with a set of code seen on the display.
Sora Shimazaki / Pexels

Yet Linux infections topped both Windows and macOS, counting for 54% of all infections. That large number is explained by the increasing usage of cloud devices that use Linux as their operating system. Many of these devices are poorly secured, making them tempting targets for bad actors wishing to gain access to a company’s internal systems.

Recommended Videos

Trojans were by far the most popular category of malware, with 80.5% of infections being made using this technique. Trailing far behind were cryptocurrency miners (11.3%) and ransomware (3.7%). Most trojan infections happened on Windows PCs, with Cobalt Strike prevailing as the trojan of choice for malware authors with a 34.5% share of infections.

Macs are vulnerable too

A physical lock placed on a keyboard to represent a locked keyboard.
piranka / Getty Images

While the report suggests that macOS is apparently a low priority for hackers and malware developers, it’s not all good news for users of Apple’s systems. Elastic Security Labs notes that nefarious use of the XMRig cryptocurrency miner “exploded” on macOS and that this kind of attack could become an “increasingly popular” way of targeting Mac users.

By far the most prevalent malware detection on macOS was MacKeeper, an app that has been designated as a “potentially unwanted program” by many antivirus apps due to the wide range of potentially exploitable permissions and access to macOS processes it obtains.

It’s well worth downloading the full report to see the complete list of findings unearthed by Elastic Security Labs. With the strong prevalence of trojans on all systems, it’s important you know how to secure your computer and protect yourself from attack. Sure, macOS is less at risk than Windows, but it only takes one careless mistake to get infected, no matter what you’re using.

Alex Blake
Alex Blake has been working with Digital Trends since 2019, where he spends most of his time writing about Mac computers…
The Mac Pro is dead at Apple, and I’ll miss the cheese-grater powerhouse
RIP Mac Pro. The Mac Studio is taking the throne, and we're okay with that.
Electronics, Computer, Pc

Apple has officially discontinued the Mac Pro. It’s been removed from Apple’s website, and Apple has confirmed to 9to5Mac that there are no plans to release a future version. The buy page now redirects to Apple’s Mac homepage, where the Mac Pro no longer exists.

Why did Apple kill the Mac Pro?

Read more
March Madness, Revisited: The AI Model Did Well. But Mad Things Still Happen
Stills from NCAA games.

(NOTE: This article is part of an ongoing series documenting an experiment with using AI to fill the NCAA brackets and see how it fares against years of human experience. The original article is as follows.)

A week ago, I wrote about entering an NCAA tournament pool with a more disciplined process than I usually use.

Read more
A simple coding mistake is exposing API keys across thousands of websites
Security gaps that are easier to miss than you think
Computer, Electronics, Laptop

After analyzing 10 million webpages, researchers have found thousands of websites accidentally exposing sensitive API credentials, including keys linked to major services like Amazon Web Services, Stripe, and OpenAI.

This is a serious issue because APIs act as the backbone of the apps we use today. They allow websites to connect to services like payments, cloud storage, and AI tools, but they rely on digital keys to stay secure. Once exposed, API keys can allow anyone to interact with those services with malicious intent.

Read more