This dangerous Mac malware can infiltrate your entire system

A newly uncovered malware designed to target Macs has been effective in obtaining access to systems and stealing sensitive data.

The discovery was detailed by internet security company ESET, which named the malware CloudMensis because of its reliance on cloud storage services.

Stock Depot / Getty Images

As reported by Bleeping Computer and PCMag, the malware can successfully take screenshots of a user’s system without their knowledge, in addition to registering keystrokes, taking files and documents (even from removable storage devices), and listing emailing messages and attachments.

Recommended Videos

CloudMensis was originally detected by ESET in April 2022. It makes use of pCloud, Yandex Disk, and Dropbox in order to execute command-and-control (C2) communication.

The malware is fairly advanced in the sense that it provides the ability to carry out numerous malicious commands, such as viewing running processes, “running shell commands and uploading the output to cloud storage,” and downloading and opening arbitrary files.

While CloudMensis has now been uncovered, the identity of those behind the malware attack remains unknown.

“We still do not know how CloudMensis is initially distributed and who the targets are,” ESET researcher Marc-Etienne Léveillé said. “The general quality of the code and lack of obfuscation shows the authors may not be very familiar with Mac development and are not so advanced. Nonetheless, a lot of resources were put into making CloudMensis a powerful spying tool and a menace to potential targets.”

ESET’s analysis reveals that the threat actors managed to infiltrate their first Mac target on February 4, 2022. Interestingly, CloudMensis has only been used a handful of times to infect a target. Furthermore, the Objective-C coding abilities from the hackers reveals they’re not well-versed in the MacOS platform, according to Bleeping Computer.

Getty Images

When ESET examined the cloud storage addresses that CloudMensis was associated with, the corresponding metadata from the cloud drives revealed “there were at most 51 victims” from February 4 until April, 2022.

Once the malware is executed on the Mac system, CloudMensis is then able to completely evade Apple’s MacOS Transparency Consent and Control (TCC) system without being detected. This feature alerts users to a window where they’ll need to grant specific permission for apps that perform screen captures or monitor keyboard events.

By avoiding TCC, CloudMensis can subsequently view the Macs’ screens and associated activity, as well as scan removable storage devices.

In any case, the malware is clearly more on the sophisticated end if it can bypass Mac’s own security measures with such relative ease. And it’s not just Macs that are exposed — PCMag highlights how the malware’s computing code confirms it can also infiltrate Intel-powered systems.

“CloudMensis is a threat to Mac users, but its very limited distribution suggests that it is used as part of a targeted operation,” ESET said. “At the same time, no undisclosed vulnerabilities (zero-days) were found to be used by this group during our research. Thus, running an up-to-date Mac is recommended to avoid, at least, the mitigation bypasses.”

If you own a Mac and want to check for viruses and malware, then be sure to head over to our guide explaining how to do so.

Editors' Recommendations

Former Digital Trends Contributor
Zak Islam was a freelance writer at Digital Trends covering the latest news in the technology world, particularly the…
Why you should buy a MacBook Pro instead of a MacBook Air

There are plenty of reasons to buy a MacBook Air instead of a MacBook Pro. If you want a MacBook on a budget, you don't necessarily need the goodies that come with upgrading to the MacBook Pro.

That being said, I'm going to argue for spending a little more. In my experience, the MacBook Pro offers several distinct advantages that help justify a higher price, especially with the introduction of the more affordable MacBook Pro 14 with the base M3. If you can stretch your budget a bit, here's why I think you should buy a MacBook Pro instead of a MacBook Air.
Setting the stage: pricing

Read more
Which color MacBook should you buy? Here’s how to pick

Apple’s MacBook laptops come in a range of colors, and selecting which is right for you can be a tricky business. Sure, it’s perhaps not as important as deciding which chip to pick or how much memory you should buy, but it’s still a vital part of the equation. After all, you’re going to see that color every time you reach for your MacBook. You don’t want it to be something that fills you with regret.

But how should you pick a MacBook color? And what do the colors even look like in the first place? We’ve got the answers to those questions in this guide. We’d also advise you to go to an Apple Store to take a look at the MacBook colors in person, as some can be hard to appreciate just by browsing Apple’s website.

Read more
Why you should buy a MacBook Air instead of a MacBook Pro

The MacBook Air has officially caught up. Now with the M3 on board, the MacBook Air has gained the benefits of the new chip, which was previously available just on the MacBook Pro and iMac.

Choosing between the M3 15-inch MacBook Air and the 14-inch MacBook Pro is tough, and requires an in-depth look at differences in ports, displays, speakers, and more. It's a legitimately hard decision to make.

Read more