Skip to main content

Malware found on some new Apple M1 Macs mystifies experts

Hackers appear to have wasted little time in targeting Apple’s recently launched Mac computers featuring its new M1 chip.

Colorado-based security firm Red Canary says it has discovered malware on nearly 30,000 Mac computers globally, though experts are currently trying to work out its precise purpose.

Recommended Videos

The malware, dubbed “Silver Sparrow,” is described as a “previously undetected strain,” though another version of it had Intel-made equipment in its sights, according to Red Canary.

According to Arstechnica, researchers have discovered that the mysterious malware is set up to check a control server once an hour. It does this to determine if there are any new commands for the malware to run. But up to now, no commands or payloads appear to have been delivered to the infected computers, leaving experts wondering what may be coming down the track.

The malicious software also incorporates a self-destruct capability that, if and when directed, enables it to remove itself from a computer.

Red Canary says that according to data provided by California-based security firm Malwarebytes, Silver Sparrow had infected 29,139 Mac computers in 153 countries as of February 17, with cases mainly concentrated in the U.S., Canada, U.K., France, and Germany.

Given what it currently knows, Red Canary says the malware presents a “reasonably serious threat” to infected Mac computers.

“Though we haven’t observed Silver Sparrow delivering additional malicious payloads yet, its forward-looking M1 chip compatibility, global reach, relatively high infection rate, and operational maturity suggest Silver Sparrow is a reasonably serious threat, uniquely positioned to deliver a potentially impactful payload at a moment’s notice,” Red Canary said in a blog post detailing what it knows so far about the malware.

It added: “The ultimate goal of this malware is a mystery. We have no way of knowing with certainty what payload would be distributed by the malware, if a payload has already been delivered and removed, or if the adversary has a future timeline for distribution. Based on data shared with us by Malwarebytes, the nearly 30,000 affected hosts have not downloaded what would be the next or final payload.”

The company’s post shares details about how it was able to detect Silver Sparrow using checks that can also uncover other MacOS threats.

Many people may still be of the belief that Apple-made computers don’t get malware. This, of course, isn’t true, and so Mac owners should be certain they have the proper protections in place to ensure their machines have the best chance of keeping hackers at bay.

UPDATE: Apple has reportedly taken steps to prevent additional Mac computers from being infected with the malware.

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Is Apple’s upcoming M4 Mac event still happening? I’m skeptical
Russian YouTuber Romancev768 with what is claimed to be a real M4 MacBook Pro unit.

Over the last few weeks, the endless stream of M4 MacBook Pro leaks has been almost inescapable. We’ve seen photos, unboxing videos, even M4 laptops reportedly going up for sale way ahead of time. Ye.t despite all that, there’s been one thing that has stopped me from fully believing that these leaks are legitimate -- despite a well-known reporter claiming that they’re authentic.

That’s because in all the leaks we’ve seen, the box of the M4 MacBook Pro has come with the same black-and-gray wallpaper that Apple used for its M3 line of MacBook Pros. It’s something that has bugged me ever since I first noticed it. But what if the use of an old wallpaper isn't proof that these leaks are fakes, but is actually a clue about what Apple is about to do next?
The wallpaper of it all

Read more
Massive M4 MacBook Pro leaks have been ‘confirmed’ to be true
Russian YouTuber Romancev768 with what is claimed to be a real M4 MacBook Pro unit.

Over the last few weeks, we’ve seen a spate of leaks showing off what are alleged to be the upcoming M4 MacBook Pro. From photos of retail boxes to full-blown unboxing videos, the internet has been awash with the next MacBook Pro, despite the fact that Apple hasn’t even announced it yet.

Despite the constant media attention, there have been consistent doubts about the leaks -- for some, they just had a few too many question marks to be trusted. Yet Bloomberg reporter Mark Gurman has just dropped a bombshell by throwing his weight behind the leaks, writing in his latest Power On newsletter: “I can confirm that these are indeed Apple’s upcoming M4 MacBook Pros.” Gurman is one of the most accurate and consistent Apple leakers in the business and claims to have sources deep inside the company. So, when he says something is genuine, there’s a good chance he’s right.

Read more
These M4 MacBook Pro leaks are a goldmine of secret info
Russian YouTuber Romancev768 with what is claimed to be a real M4 MacBook Pro unit.

Apple's known for locking down its secrets under lock and key. But not these past few weeks.

The company hasn’t even announced the M4 MacBook Pro, yet we’ve apparently learned pretty much everything there is to know about the upcoming laptop thanks to a series of purported high-profile leaks and unboxing videos that have shown off the device from every angle. For a firm as security conscious as Apple, having the MacBook Pro spoiled in this way is close to catastrophic.

Read more