Common Windows Malware Can Now Infect Macs

A common form of malware on Windows systems has been modified into a new strain called "XLoader" that can also target macOS (via Bleeping Computer).

macOS Malware Feature
Derived from the Formbook info-stealer for Windows, XLoader is a form of cross-platform malware advertised as a botnet with no dependencies. It is used to steal login credentials, capture screenshots, log keystrokes, and execute malicious files. The malware was discovered by security researchers at Check Point Software.

A server hosting the macOS version of XLoader is available to bad actors on the dark web for $49 per month. Check Point tracked XLoader for a six-month period, seeing requests from 69 countries, indicating significant use across the world. More than half of all victims were based in the United States.

Formbook continues to be a prevalent threat, being part of over 1,000 malware campaigns in the last three years, and XLoader is expected to have even wider use given its cross-platform capability and greater level of sophistication.

Head of Cyber Research at Check Point, Yaniv Balmas, said that macOS's growing popularity has exposed it to increasing attention from cybercriminals, who see the platform as a worthwhile target.

While there might be a gap between Windows and macOS malware, the gap is slowly closing over time. The truth is that macOS malware is becoming bigger and more dangerous.

According to Check Point, XLoader is stealthy enough for it to remain hidden to most users. It is possible to check for its presence by using macOS's Autorun to check the username in the OS and look into the LaunchAgents folder, where entries with suspicious filenames should be deleted.

Tag: Malware

Popular Stories

iOS 26 Battery Glass Feature

iPhone 16 Pro Max 80% Charge Limit: One Year Later, Was It Worth It?

Wednesday September 24, 2025 3:58 pm PDT by
With the iPhone 15 series, I did an experiment and kept my iPhone's Charge Limit set at 80 percent for an entire year. It provided an interesting look at the impact of charge limits on battery longevity, so I decided to repeat it for the iPhone 16 line. Since September 2024, my iPhone 16 Pro Max has been limited to an 80 percent charge, with no cheating. As of today, my battery's maximum...
AirPods Pro 3 Newsroom

Apple's 'Back to School' Offer Ends Soon, Now Applies to AirPods Pro 3

Wednesday September 24, 2025 7:20 am PDT by
Apple's annual "Back to School" promotion for students ends soon, so act fast if you want to score free AirPods with the purchase of an eligible new Mac or iPad. Until Tuesday, September 30, college students and qualifying educational staff in the U.S. can receive free AirPods 4 with Active Noise Cancellation when they purchase an eligible new Mac or iPad from Apple. This is a $179 value. ...
iphone 17 pro dark blue 1

Apple Blames In-Store MagSafe Chargers for iPhone 17 Pro Display Model Scratches

Wednesday September 24, 2025 10:22 am PDT by
The marks on the iPhone 17 Pro models that people have noticed at Apple retail stores are caused by the chargers that Apple uses, Apple confirmed today. Apple told 9to5Mac that worn MagSafe charging stands in stores are causing marks on the iPhone 17 Pro and iPhone 17 Pro Max. Apple says that the marks are not scratches, and are instead material transfer from the stand to the phone. The...
Home Hub Command Center with Dome Base Feature

Apple Working on All-New Operating System

Thursday September 25, 2025 1:11 pm PDT by
Apple is developing an all-new operating system codenamed "Charismatic," according to Bloomberg's Mark Gurman. Apple smart home hub concept based on rumors This is likely Apple's long-rumored "homeOS" operating system. In a report last month, Gurman said both Apple's rumored smart home hub in 2026 and tabletop robot in 2027 will run the new operating system. He said the software platform ...
iPhone 17 Pro Colors

Skipped the iPhone 17 Pro? Here's What is Rumored for iPhone 18 Pro

Tuesday September 23, 2025 8:55 am PDT by
While the iPhone 18 Pro and iPhone 18 Pro Max are still a year away, there are already a few rumors about the devices that offer an early look ahead. Below, we have recapped some of the early iPhone 18 Pro rumors so far. This story was published previously, and it has been updated to reflect the latest rumors. Many early rumors prove to be true, but nothing is confirmed yet, and Apple's...
iOS 26

Everything New in iOS 26.1 Beta 1

Monday September 22, 2025 12:44 pm PDT by
Apple released the first beta of iOS 26.1 today, just a week after launching iOS 26. iOS 26.1 mainly adds new languages to Apple Intelligence, but there are a few other features that are worth knowing about. New Apple Intelligence Languages Apple Intelligence is now available in Danish, Dutch, Norwegian, Portuguese (Portugal), Swedish, Turkish, Chinese (Traditional), and Vietnamese. AirPo...
ios 26 digital id passport wallet

Apple Confirms iOS 26 Wallet Passport Feature is Coming in 2025

Tuesday September 23, 2025 1:06 pm PDT by
Digital ID, the iOS 26 feature that lets U.S. passport holders add their passports to the Wallet app, is coming later in 2025, Apple confirmed today. Apple updated the release timing wording of Digital ID on its iOS 26 features page. "Digital ID will be coming later this year with US passports only," it reads. Prior to today, the footnote for the feature said "Digital ID will be available ...
apple tv 4k new orange

Next Apple TV Expected to Launch This Year With These New Features

Monday September 22, 2025 10:00 am PDT by
The next Apple TV is expected to be released later this year, and a handful of new features and changes have been rumored for the device. Below, we recap what to expect from the next Apple TV, according to rumors. Likely Features N1 Chip With Wi-Fi 7 Last year, Bloomberg's Mark Gurman said the next Apple TV would be equipped with Apple's own combined Wi-Fi and Bluetooth chip, which is...
iPhone 17 Pro USB C Port

iPhone 17 Pro Max's USB-C Charging Speeds Tested With Apple Chargers

Monday September 22, 2025 7:29 am PDT by
The website ChargerLAB has tested the iPhone 17 Pro Max's USB-C charging speeds with a variety of Apple's chargers, from 18W to 140W. The device reached a peak charging speed of around 36W with the following Apple chargers:40W Dynamic Power Adapter with 60W Max 61W USB-C Power Adapter 67W USB-C Power Adapter 70W USB-C Power Adapter 96W USB-C Power Adapter 140W USB-C Power AdapterFor...

Top Rated Comments

Sciomar Avatar
55 months ago

No matter what these Mac’s are protected. Let’s be real here.
I know we should all know this but for everyone in the room, Mac's have always been able to get a virus. They were such a small subset of the computing world the payoff wasn't huge. Things have changed with the more mainstream adoption of Macs and now it's open season for the bad guys.
Score: 33 Votes (Like | Disagree)
npmacuser5 Avatar
55 months ago
How does one get this malware? Important to know one has it but how did one get it just as important.
Score: 24 Votes (Like | Disagree)
skitidetdu Avatar
55 months ago

It is possible to check for its presence by using macOS's Autorun to check the username in the OS and look into the LaunchAgents folder, where entries with suspicious filenames should be deleted.
Can somebody explain what this means?

Edit: found a LaunchAgents folder in the library. Don't understand what AutoRun is
Score: 23 Votes (Like | Disagree)
urgs Avatar
55 months ago

Infection path would be good information.

Also, I generally find LittleSnitch to be a great defense against this kind of thing (as long as the virus doesn't disable it). It may still exist, but you can identify it by network access.

Can somebody explain what this means?

Edit: found a LaunchAgents folder in the library. Don't understand what AutoRun isFound something at 9to5mac
Found something at 9to5mac

1. Go to /Users/[username]/Library/LaunchAgents directory
2. Check for suspicious filenames in this directory (example below is a random name)

/Users/user/Library/LaunchAgents/com.wznlVRt83Jsd.HPyT0b4Hwxh.plist

if there is a file named like above, it's very likely you have been infected
Score: 22 Votes (Like | Disagree)
Blackstick Avatar
55 months ago
So XProtect gets new definitions and this becomes a non-issue...
Score: 13 Votes (Like | Disagree)
TheYayAreaLiving ?️ Avatar
55 months ago
No matter what these Mac’s are protected. Let’s be real here.

When was the last time you encountered your Mac got a virus?
Score: 13 Votes (Like | Disagree)