Security Bite: Threat landscape review (September)

Security Bite: Threat landscape review (September)

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple. Every few months, I sit down to look back at the Mac threat landscape, and every time I expect to write about something new. This time I can’t. But that doesn’t mean nothing is happening. In fact, the opposite. Since I published the Security Bite Q1 2026 review, we’ve seen ClickFix go from the new kid on the block and the technique to watch to now the default delivery method for almost every new Mac stealer. Threat actors are getting much better at using it too (I suppose the kids would call this “locked in”). Recently we’ve seen attackers implement persistence, backdoors, and even infrastructure that hides inside Apple’s own services. Here’s what you should know as a security practitioner or a malware-fearing Mac owner… ClickFix is an on-ramp for everything right now To no one’s surprise, Apple’s 26.4 Terminal prompts didn’t slow this attack vector down. Nearly every new Mac malware family from the past few months arrived the same way: a fake CAPTCHA or “fix” page that gets the victim to paste a command into Terminal themselves. ClickLock, discovered by Group-IB. A new Go-based stealer Huntress spotted in August. The latest MacSync variant, which Kaspersky found spreading through pages posing as Homebrew and a disk space cleanup tool. More on each soon. What makes ClickFix so successful is that it doesn’t need to go up against Gatekeeper, notarization, XProtect, or any of the Mac’s incredibly capable antivirus tools. This is really because the user is coerced into infecting themselves by running the script. Apple’s warning prompts were a good first step, but attackers are scrappy and will always find ways around. Like Script Editor. Stealers are evolving into something much worse So, ClickFix is the delivery technique. Now let’s talk about the payload. In its old school form, a Mac infostealer was very much a smash and grab. It would run once, dump your passwords and crypto wallets to something like a Telegram bot, and then vanish. That’s certainly not the case anymore. Just this year, we’ve seen examples like ClickLock that social engineer users into giving up their system password and leave a backdoor behind for round two. ClickLock stealer malware presenting fake alert to get the user’s system password. Doesn’t go away until the user enters the correct one (it verifies). MacSync, which came into the world as an AMOS lookalike, picked up a backdoor module too. Moonlock Lab put it best in its mid-year report, saying the 2026 model isn’t a stealer, it’s a persistent implant that happens to start with stealing. Arguably, the more interesting change is how they’re hiding now. MacSync’s latest version actually pulls its commands from a public iCloud calendar, so anyone watching network traffic just sees the Mac talking to Apple. CrashStealer, found by Jamf Threat Labs in July, posed as Apple’s own crash reporting framework inside a notarized app, so Gatekeeper just let it right through. Neither is a flaw in macOS. It’s attackers figuring out that the easiest way past Mac’s built-in defense mechanisms is to look like something trusted from Apple. What you can do as a user or practitioner There’s not much users can do beyond updating to the latest versions of the operating system. As of today, that means iOS 27 or 26.7 and macOS Golden Gate or Tahoe 26.7. I would also recommend turning off Screen Sharing if you don’t use it. And the big one: NEVER paste a command into Terminal given to you by a website or pop up alert. Tibit if you’re defending a Mac fleet: the single most valuable stealer detection right now is Terminal, Script Editor, or osascript spawning from a browser. Pair it with alerts for curl or base64 piped directly into a shell because the first stage doesn’t go to disk. If you’re only scanning files, it’s too late. Security Bite: The last 24 hours at Meta were “not-a-musing” Security Bite: iOS 27 now lets apps ask your iPhone if you’re being scammed Security Bite Podcast: What’s hitting Macs so far in 2026, plus OBTS v9 preview (Part 2) Security Bite: Apple’s baffling bug bounty changes finally make sense Security Bite is 9to5Mac’s weekly deep dive into the world of Apple security. Each week, Arin Waichulis unpacks new threats, privacy concerns, vulnerabilities, and more, shaping an ecosystem of over 2 billion devices. Every other week on the Security Bite Podcast, he sits down with experts in the field to break down the most pressing topics. Follow Arin: Twitter/X,LinkedIn, Threads FTC: We use income earning auto affiliate links. More.

Original Source

Read the full article at 9to5mac →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.