Skip to main content

This dangerous Mac malware can infiltrate your entire system

A newly uncovered malware designed to target Macs has been effective in obtaining access to systems and stealing sensitive data.

The discovery was detailed by internet security company ESET, which named the malware CloudMensis because of its reliance on cloud storage services.

A large monitor displaying a security hacking breach warning.
Stock Depot / Getty Images

As reported by Bleeping Computer and PCMag, the malware can successfully take screenshots of a user’s system without their knowledge, in addition to registering keystrokes, taking files and documents (even from removable storage devices), and listing emailing messages and attachments.

Recommended Videos

CloudMensis was originally detected by ESET in April 2022. It makes use of pCloud, Yandex Disk, and Dropbox in order to execute command-and-control (C2) communication.

The malware is fairly advanced in the sense that it provides the ability to carry out numerous malicious commands, such as viewing running processes, “running shell commands and uploading the output to cloud storage,” and downloading and opening arbitrary files.

While CloudMensis has now been uncovered, the identity of those behind the malware attack remains unknown.

“We still do not know how CloudMensis is initially distributed and who the targets are,” ESET researcher Marc-Etienne Léveillé said. “The general quality of the code and lack of obfuscation shows the authors may not be very familiar with Mac development and are not so advanced. Nonetheless, a lot of resources were put into making CloudMensis a powerful spying tool and a menace to potential targets.”

ESET’s analysis reveals that the threat actors managed to infiltrate their first Mac target on February 4, 2022. Interestingly, CloudMensis has only been used a handful of times to infect a target. Furthermore, the Objective-C coding abilities from the hackers reveals they’re not well-versed in the MacOS platform, according to Bleeping Computer.

A depiction of a hacker breaking into a system via the use of code.
Getty Images

When ESET examined the cloud storage addresses that CloudMensis was associated with, the corresponding metadata from the cloud drives revealed “there were at most 51 victims” from February 4 until April, 2022.

Once the malware is executed on the Mac system, CloudMensis is then able to completely evade Apple’s MacOS Transparency Consent and Control (TCC) system without being detected. This feature alerts users to a window where they’ll need to grant specific permission for apps that perform screen captures or monitor keyboard events.

By avoiding TCC, CloudMensis can subsequently view the Macs’ screens and associated activity, as well as scan removable storage devices.

In any case, the malware is clearly more on the sophisticated end if it can bypass Mac’s own security measures with such relative ease. And it’s not just Macs that are exposed — PCMag highlights how the malware’s computing code confirms it can also infiltrate Intel-powered systems.

“CloudMensis is a threat to Mac users, but its very limited distribution suggests that it is used as part of a targeted operation,” ESET said. “At the same time, no undisclosed vulnerabilities (zero-days) were found to be used by this group during our research. Thus, running an up-to-date Mac is recommended to avoid, at least, the mitigation bypasses.”

If you own a Mac and want to check for viruses and malware, then be sure to head over to our guide explaining how to do so.

Zak Islam
Former Digital Trends Contributor
Zak Islam was a freelance writer at Digital Trends covering the latest news in the technology world, particularly the…
I tested the most popular free antivirus apps for Mac. Here are the very best
A MacBook Air is shown with the Bitdefender for Mac dashboard open.

The best free antivirus software for your Mac offers robust protection without breaking the bank. Although macOS was once an unlikely target for hackers, that's changing. As Apple computers become more popular, malware prevention is increasingly important to safeguard your personal and financial data.
Finding the best antivirus software can be challenging. While subscription prices are affordable, your budget might already be tight. Thankfully, there are several good, free malware solutions for macOS. Here are our top picks for free antivirus software for Mac, with each specially tailored to protect your Apple computer.
Avast One Basic

While Avast One Basic is free and shows no ads, this powerful antivirus software still protects your Mac from malware infections, and blocks new threats before they become a problem. Perhaps more impressive is the Web Shield feature that identifies malicious downloads and prevents access to hazardous websites, halting phishing attempts and other online dangers.

Read more
The MacBook Air just got a surprise upgrade that everyone will love
The MacBook Air on a white table.

Apple announced an unexpected change to the current M2 and M3 MacBook Air today: more memory. Alongside the overarching bump to RAM in base configurations of the M4 iMac, Mac mini, and MacBook Pro, Apple also announced that the 8GB versions of the M2 and M3 MacBook Air have also been removed from the lineup.

Starting today, the M2 MacBook Air and M3 MacBook Air will both have 16GB as the starting configuration. But here's the kicker: Apple isn't raising prices. That means if you'd spent $1,199 on an M2 MacBook Air with 16GB of RAM yesterday, you'd be getting it today for just $999. As much as that'll sting for recent buyers, it's great news for people buying MacBook Airs this holiday season.

Read more
Apple’s M4 iMac brings next-gen power to your desktop
People using the Apple iMac with M4 chip.

Apple has brought its M4 chip to the iMac, making it the first Mac to get Apple’s latest silicon chip. The update also brings new colors and a significant performance improvement for the all-in-one desktop computer, and it comes a year after it received the previous-generation M3 chip. As with the previous M1 and M3 iMacs, the M4 model is compatible with Apple Intelligence.

It comes at the beginning of a week of product releases from Apple, with the company previously teasing that it had much more to reveal in the coming days. The updates could see the entire Mac lineup receive some variant of the M4 chip (including more powerful M4 Pro, M4 Max and M4 Ultra editions) over the coming months.

Read more