October 1, 2026 15 min read

Mac Malware Trend Report

Point Wild Threat Research Lat61 Threat Intelligence Team
Mac Malware Trend Report

Reporting period:  July – September 2026

Sourcing:  Public threat intelligence, merged with Point Wild Q3 processed samples

1. Executive Summary

Public threat intelligence published between July and September 2026 shows continued convergence between macOS and Windows attack surfaces, sustained dominance of social-engineering delivery (ClickFix-style Terminal-paste attacks) over software exploitation, and growing operator-grade sophistication in the macOS infostealer market. This report consolidates the quarter’s key public disclosures into a single reference and closes with a myth-vs-fact section suitable for security awareness communications.

Key findings

  •  Point Wild processed 37,898 macOS malware samples during Q3 2026; Trojan and Infostealer threats were the single largest category at 54.2% (20,524 samples), ahead of PUA at 40.8% (15,450 samples), a distribution that closely tracks Jamf Threat Labs’ public estimate that Trojans now account for roughly half of all Mac malware.
  • ClickFix continues to be a prominent macOS malware delivery vector in Q3, and was featured heavily in infostealer campaigns such as ClickLock, Odyssey, AMOS, and MacSync.
  • Mac and Windows threat infrastructure increasingly overlap: multiple campaigns served matched payloads to both platforms from shared servers and operators (Moonlock, H1 2026).
  • Odyssey Stealer led the macOS stealer field at 62.7% of stealer detections in H1 2026, ahead of AMOS and smaller families (Moonlock).
  • A verified, hijacked brand account (HBO Max on Reddit) was used to distribute a Mac-targeting infostealer via paid ads in September 2026, demonstrating that trusted-source assumptions no longer hold.
  • CVE-2026-39118 allows a standard, non-admin macOS account to silently disable Kandji and CrowdStrike, materially weakening enterprise endpoint defenses if unpatched.
  • A DPRK-linked campaign (“EtherHiding”) was observed resolving its C2 address from a Polygon blockchain smart contract rather than a hardcoded domain, the first Q3-dated evidence of blockchain-based C2 reaching macOS.
  • Apple’s macOS Tahoe 26.4 introduced a native warning against Terminal-paste attacks, a meaningful but partial mitigation, since it does not address trojanized-installer or fake-app vectors.

2. Threat Landscape Overview

For most of macOS malware’s history, the platform benefited from a straightforward economic argument: attackers build where the users are, and that has historically meant Windows. Public data through 2026 shows that argument weakening. Jamf Threat Labs, analyzing telemetry from more than 150,000 devices for its 2026 Security 360 report, found Mac market share grew 16.4% year over year in 2025, with Trojans now accounting for roughly half of all Mac malware, a shift in composition, not just volume.

Two user segments are absorbing a disproportionate share of the increased attacker interest: developers, whose credentials (GitHub tokens, npm tokens, cloud keys, SSH keys) unlock infrastructure well beyond a single laptop; and creative/knowledge work professionals, whose Macs increasingly hold corporate data and admin sessions inside enterprise networks.

Apple’s native controls  Gatekeeper, notarization, and XProtect remain effective at what they were designed to do: block unsigned or unnotarized applications from executing. Attackers have adapted by avoiding app execution entirely, instead distributing malware as scripts that the user is persuaded to run directly, as documented in Red Canary’s Threat Detection Report.

Sources: Jamf Threat Labs (Security 360, 2026); Red Canary Threat Detection Report.

3. Anatomy of a ClickFix Attack

Nearly every campaign in this quarter’s docket follows the same technical pattern. Understanding that pattern matters more than tracking any single campaign name, since the pattern outlives the name.

Stage 1: The lure

A page, a fake CAPTCHA, a fake download screen, or a fake system-utility notification tells the visitor something needs fixing before they can continue. Microsoft’s tracking of ClickFix campaigns since February 2026 documents this as the near-universal opening move.

Stage 2: The command

The page supplies a short shell command, usually already copied to the clipboard, and instructs the visitor to paste it into Terminal. This step carries the entire attack: no exploit is required, because the user’s own account permissions execute the payload.

Stage 3: The loader

The initial command typically fetches a second-stage script, a zsh loader that decodes a base64-and-gzip-compressed payload and executes it via eval. The script fingerprints the machine (macOS version, installed security tools, VM or sandbox indicators) before proceeding.

Stage 4: The harvest

Only after that reconnaissance does the payload target its objectives. Public analyses of AMOS, Odyssey, and Realst show them going directly to known file paths: 1Password’s vault directory, Telegram’s session data, Discord tokens, and cryptocurrency wallet files, alongside browser-stored credentials and autofill data.

Stage 5: The exfiltration

Stolen data is transmitted out, frequently over infrastructure shared with the Windows side of the same campaign. The infection typically produces no visible symptoms on the host, which is why many cases surface later via a stolen-credential marketplace or a fraud alert rather than at the point of compromise.

Sources: Microsoft Threat Intelligence; Unit 42; Red Canary.

4. Top Exploited Vulnerabilities

This quarter’s clearest confirmed-exploitation story wasn’t a new malware family; it was a critical flaw in macOS’s built-in screen sharing service.

4.1  CVE-2026-65400  Screen Sharing Pre-Authentication Bypass (Critical)

 

Detail Finding
Component screen sharing — macOS’s built-in Screen Sharing / VNC service (TCP port 5900)
Root cause The daemon’s Secure Remote Password (SRP) frame-length validator incorrectly returns a stale “success” status, so a connection is treated as authenticated when it never actually completed authentication
Impact A network attacker connects with no valid credentials at all and gains root-level remote code execution
Affected versions macOS Tahoe < 26.6.1, Sequoia < 15.7.9, Sonoma < 14.8.9
Patched August 6, 2026
Rescored & added to CISA KEV August 18, 2026 (CVSS raised from an initial 7.1 to 9.8 after confirmed exploitation)
Confirmed exploitation Dutch NCSC and Microsoft both confirmed active exploitation. Microsoft’s telemetry showed attackers authenticating as root via Screen Sharing, transferring an SSH key, establishing SSH persistence, wiping logs, modifying firewall (pf) rules, and deploying the XMRig cryptominer
Mitigation if unpatched Disable Screen Sharing (System Settings → General → Sharing), or block inbound access to port 5900 at the firewall

Sources: The Hacker News; Huntress; Tanium; Arctic Wolf; Microsoft (Aug 18 exploitation advisory).

4.2  Related Screen Sharing Bugs, Same Disclosure Window

Two sibling flaws in the same subsystem were patched three weeks earlier, on July 27, and were initially believed to have closed the Screen Sharing attack surface entirely. They hadn’t; CVE-2026-65400 above was still live.

CVE Type CVSS Requires Confirmed exploited?
CVE-2026-43760 Post-auth file-operation confusion 8.6 Attacker already has the legacy VNC password No
CVE-2026-43777 Denial of service 7.5 Network access to the service No

The distinction that matters: CVE-2026-43760 needed a password the attacker would already have to possess. CVE-2026-65400 needed nothing, which is exactly why it, and not its higher-CVSS-at-disclosure sibling, is the one that ended up in CISA’s KEV catalog and deployed on real machines.

5. Mac Supply-Chain Threats: When Trusted Development Tools Become the Attack Surface

Rust package supply-chain attack  August 2026

On August 20, 2026, attackers published malicious versions of three Rust packages on crates.io. Security researchers reported that the macOS payload functioned as a RAT/credential stealer, targeting:

  • Cloud credentials
  • SSH keys
  • Cryptocurrency wallet data
  • Browser profiles
  • Other host information

On macOS, the malware also established persistence through a LaunchAgent and communicated with attacker-controlled infrastructure. The malicious packages were reportedly available for approximately two hours before removal.

This is particularly relevant to a Mac-only report because the attack demonstrates how developers can become an infection path: a compromised software dependency can introduce malware into the developer’s macOS environment.

Another important Mac supply chain case

XCSSET v40 is also highly relevant, although its activity began earlier in 2026. Palo Alto Networks reported that since April 2026, XCSSET has spread through Xcode projects of legitimate applications, targeting developers and potentially downstream users. The malware can infect existing Xcode projects and includes credential theft, browser hijacking, clipboard monitoring, and data exfiltration capabilities.

6. Ransomware: Limited Evidence of Direct macOS Targeting

Unlike Windows and Linux environments, Q3 2026 did not produce a clearly documented widespread macOS ransomware campaign with confirmed victims in the public research reviewed. Existing macOS ransomware demonstrates that file encryption is technically feasible, but recent Mac-focused activity continues to show greater emphasis on credential theft, information stealing, social engineering, and data exfiltration rather than traditional file-encrypting ransomware.

7. Key Incidents and Campaigns Q3 2026

The following table summarizes the quarter’s material public disclosures in chronological order.

Date Campaign / Disclosure Summary Source
Early Jul ClickLock Stealer Modular stealer spread via ClickFix pages on compromised WordPress sites; 100+ victims across 33 countries within two months, no exploit or elevated privileges required. Group-IB / Malwarebytes
Ongoing Fake Homebrew / TradingView / LogMeIn sites 85+ phishing domains impersonating developer tools, prompting base64-encoded Terminal commands that install Odyssey Stealer or AMOS. Hunt.io / OffSeq
Jul 16 Moonlock Mid-2026 Threat Report ClickFix confirmed as top delivery method; adware ~65% of detections; Odyssey leads stealer detections at 62.7%. Moonlock (MacPaw)
Jul 22 EtherHiding: Polygon blockchain C2 macOS implant resolved its C2 address from a Polygon smart contract via a keyless eth_call instead of a hardcoded domain; fileless persistence via a Launch Agent; linked with moderate confidence to DPRK’s “Contagious Interview” campaign. Prophet Security
Aug 5 New AMOS sample (“macOS toolkit” lure) Fresh Atomic macOS Stealer infection generated from a fake installation-guide page at getmacoscloud[.]com. Unit 42
Aug CVE-2026-39118 disclosed Standard, non-admin accounts can silently disable Kandji and CrowdStrike enterprise endpoint tools. Mac Observer / Moonlock
Sep 6–15 HBO Max verified Reddit account hijacked A compromised account ran paid ads for a fake macOS app; ClickFix-style Terminal command delivered an infostealer. TechCrunch / Hudson Rock
Ongoing Sapphire Sleet (DPRK) Fake job interviews and LinkedIn recruitment lures used to get Mac users to run malicious files disguised as updates; targets finance, crypto, blockchain. Microsoft Threat Intelligence

Apple shipped a partial mitigation during this window: macOS Tahoe 26.4 introduced a system warning (“Possible malware, Paste blocked”) that intercepts Terminal-paste attempts triggered from the clipboard. This addresses the ClickFix vector specifically but does not mitigate trojanized-installer or fake-app campaigns, which remain effective regardless of OS version.

8. Metrics and Statistics

8.1  Point Wild Processed Samples — Q3 2026

Point Wild Threat Intelligence processed 37,898 Mac malware samples internally during Q3 2026. Trojan and Infostealer detections were the dominant category by a wide margin, consistent with the credential- and wallet-theft objective seen across the public campaigns catalogued in Section 4.

Category Samples Share
Trojan + Infostealer 20,524 54.2%
PUA (Potentially Unwanted Application) 15,450 40.8%
Backdoor 1093 2.9%
PSW (password stealer) 329 0.9%
Downloader 279 0.7%
Hacktool 223 0.6%

Source: Point Wild Threat Intelligence, internal Q3 2026 processing samples. “Backdoor,” “PSW,” “Downloader,” and “Hacktool” together make up the 5.1% “Others” share shown in the chart.

This distribution corroborates the public data in Section 8.2 below rather than diverging from it: Jamf Threat Labs’ independent estimate that Trojans account for roughly half of all Mac malware lines up closely with Point Wild’s 54.2% Trojan+Infostealer share, despite the two figures coming from unrelated sources.

8.2  Public Vendor Metrics

Figures below are drawn from named public vendor telemetry rather than a single unified dataset. Each figure is attributed individually; they should not be summed or directly compared across vendors, or with the Point Wild figures above.

Metric Value Source
Mac malware detections that are adware (mid-2026) ~65% Moonlock
Share of stealer detections that are Odyssey Stealer 62.7% Moonlock
Mac YoY market-share growth (2025) 16.4% Jamf Threat Labs
Share of Mac malware that is Trojan-based (2025 data) ~50% Jamf Threat Labs
Phishing domains in the Homebrew/TradingView/LogMeIn cluster 85+ Hunt.io
ClickLock Stealer victims/countries (first 2 months) 100+ / 33 Group-IB
macOS malware families in a single DPRK-linked engagement 7 Mandiant (UNC1069)

Top Malware Families Observed in Q3 2026 (Ranked)

# Family Type Q3 2026 Evidence Delivery / Notes
1 Odyssey Stealer (ex-Poseidon; AMOS fork) Infostealer (MaaS) Surge reported 8 Jul across 100+ countries; top stealer share in latest telemetry ClickFix → base64 AppleScript via osascript; steals browsers, 16+ wallet apps, SSH/cloud/Docker configs; swaps wallet apps for drainers
2 Atomic macOS Stealer (AMOS) lineage Infostealer (MaaS) Unit 42 infections 31 Jul & 5 Aug with rapidly rotating C2; most-submitted family on VirusTotal Fake ‘macOS toolkit’, cracked-app and Homebrew lures; Script Editor applescript:// bypass of Tahoe 26.4 paste warning
3 MacSync Stealer (Mac.c successor) Infostealer (MaaS) Seqrite August telemetry: US, UK, Germany, Japan, Canada lead Malvertising → ClickFix; fileless; chunked exfil via dd + HTTP PUT; self-cleaning
4 SHub Stealer / SHub.Loader (incl. SHub Reaper) Stager + infostealer Dominant stager family in latest telemetry (90.7%) Fake utility sites (e.g., cleaner apps); wallet backdooring; heartbeat remote commands
5 ClickLock Stealer Modular infostealer ≥100 victims in 33 countries, >50% Europe (reported Jul) ClickFix on compromised WordPress; Telegram infra; no privileges required
6 Go-based ClickFix stealer (Huntress) Infostealer Reported Aug; hosted on sanctioned Aeza bulletproof ranges Fake CAPTCHA → Bash profiler → arch-matched Mach-O; Keychain & wallet theft
7 DPRK tool sets (macWebT/Axios RAT, UNC1069 families, RustDoor, Gaslight) Backdoors / RATs Thin but persistent band in telemetry; Axios fallout advisories into Jul Fake interviews, fake Zoom/Teams fixes, poisoned npm; crypto & developer targeting
8 Adware (AdLoad, Bundlore, Pirrit families) Adware / PUA Largest share of raw detections by volume Bundled installers; low severity but high volume; can install persistent LaunchDaemons

8.3 Family-Level Trend Observations

  • Consolidation around the AMOS codebase. Odyssey, SHub and several smaller families share AMOS-derived architecture (AppleScript payload, fake password prompt, ZIP exfiltration), so signature-based family counts understate the lineage’s true dominance.
  • MaaS and loader-as-a-service specialisation. Traffer teams rent shared delivery infrastructure and swap stealer payloads, meaning one lure domain can serve several families.
  • Code-signing abuse is routine. Over half of malicious Mach-O uploads in H1 were signed, and about one-fifth carried valid or recently revoked Apple Developer certificates.
  • AI-tool impersonation. Fake installers for AI developer tools ranked second only to cracked creative software among lure file names.
  • Volume vs harm mismatch. Adware dominates detections, but stealers and backdoors account for almost all real-world damage and are the priority for detection engineering.

9. Threat Actor Profiles

9.1  “Rodrigo4” — AMOS → Poseidon → Odyssey (financially motivated, MaaS)

Odyssey Stealer is the third generation of a single lineage rather than a new development. AMOS (Atomic macOS Stealer) pioneered browser-extension and desktop-wallet theft as a malware-as-a-service offering. A developer using the alias Rodrigo4 forked it into Poseidon Stealer with wider malvertising distribution; after selling Poseidon, the same actor rebuilt the codebase again as Odyssey, engineered to bypass current macOS hardening. The operation shows a deliberate geographic preference for the US, EU, and Canada while avoiding CIS countries, consistent with Russian-aligned underground forum norms.

9.2  Sapphire Sleet (state-sponsored, DPRK)

Active since at least 2020 and tracked closely by Microsoft, Sapphire Sleet targets finance, cryptocurrency, and blockchain organizations to generate revenue for its state sponsor. Its 2026 activity relied almost entirely on social engineering, fake job interviews, recruiter outreach and “in-call fixes” that ask a target to run a file to resolve a fabricated technical problem rather than a macOS software exploit.

A related July 2026 disclosure, dubbed EtherHiding, found a macOS implant resolving its command-and-control address from a smart contract on the Polygon blockchain rather than a hardcoded domain, assessed with moderate confidence as linked to the same DPRK “Contagious Interview” tradecraft. Because the technique requires no attacker-owned server, it resists conventional domain and IP takedowns; researchers found that monitoring the contract itself, rather than chasing rotating domains, recovered the operator’s complete C2 rotation history and wallet cluster. This is the concrete Q3 case behind the blockchain-based C2 trend flagged in Section 11’s Q4 outlook.

Sources: Red Canary; WizardCyber; Microsoft Threat Intelligence.

10. Mac Malware: Myths vs. Facts

Myth Fact (source)
“Macs don’t get viruses.” Apple has confirmed Macs get malware. macOS is harder to infect than Windows historically was, but never immune.  (Malwarebytes; O’Reilly, The Art of Mac Malware)
“Gatekeeper and notarization mean any app I run is safe.” Gatekeeper checks apps only at launch. Every Q3 case in this report avoided that check by never requiring an app launch — the user was asked to paste a script into Terminal instead.  (Red Canary)
“I only download from official sources, so I’m not at risk.” The September HBO Max campaign ran through a verified brand account and a paid ad slot. Fake Homebrew/TradingView pages were built to be indistinguishable from the real tools.  (TechCrunch; Hudson Rock; Hunt.io)
“Mac threats and Windows threats are separate problems.” Campaigns this year served matched macOS and Windows payloads from shared infrastructure; a DPRK-linked intrusion deployed 7 macOS families alongside Windows tooling in one engagement.  (Moonlock; Mandiant)
“Mac malware is unsophisticated — only a risk for careless users.” A state actor, an active CVE disabling enterprise EDR tools, and stealers purpose-built to target 1Password and crypto-wallet file paths describe operator-grade tooling, not user carelessness.  (Microsoft; Mac Observer; CoreLock)

11. Outlook for Q4 2026

Public tracking from Moonlock and Red Canary points to continuity rather than a new attack category. Trends to monitor heading into Q4:

  • Continued language diversification beyond C/C++ into Go, Rust, Nim, and Crystal to evade signature-based detection.
  • Early experimentation with blockchain- and smart-contract-based command-and-control, migrating from Windows-side DPRK operations.
  • Proxy-mesh modules becoming a default rather than advanced feature, complicating infrastructure takedowns.
  • Tighter operational parity between macOS and Windows campaigns from well-resourced actors.
  • High probability of further worm-style registry compromises, including expansion to PyPI and other ecosystems.
  • Likely addition of CVE-2026-65414 (Bluetooth) or another September CVE to CISA KEV if public exploit details emerge.
  • Gatekeeper bypass CVEs fixed in September are likely to be weaponised by stealer operators against unpatched Macs.

12. Sources

Keep reading