Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

Banshee Stealer Variant Targets macOS Users

January 10, 2025
Reading Time: 2 mins read
in Alerts
New Banshee Stealer Variant Targets macOS with Advanced Evasion Tactics

A new variant of Banshee Stealer has resurfaced with advanced evasion tactics, targeting macOS users. Originally thought to be dormant after its source code leaked in late 2024, this variant now incorporates encryption techniques derived from Apple’s XProtect. This modification allows the malware to obfuscate its strings, bypassing antivirus systems and increasing its chances of successful infections. Check Point Research, who uncovered this development, noted that the malware now poses a significant risk to over 100 million macOS users globally.

The Banshee Stealer variant is being distributed through phishing websites and fake GitHub repositories, which are designed to appear as legitimate software like Google Chrome, Telegram, and TradingView. These deceptive tactics are meant to lure unsuspecting users into downloading the malware, which then steals sensitive data. This includes information from web browsers, cryptocurrency wallets, and files with specific extensions. The malware is being offered under a malware-as-a-service (MaaS) model, making it accessible to other cybercriminals for $3,000 per month.

Despite the initial setback caused by the leak of its source code in November 2024, the Banshee Stealer campaign has continued. Check Point Research reported detecting ongoing campaigns still distributing the malware, though it remains unclear whether these campaigns are being run by the original threat actors or their customers. The same campaigns are targeting both macOS and Windows users, with Banshee Stealer targeting the former and Lumma Stealer attacking the latter. This suggests a wide-reaching effort to compromise as many systems as possible.

A notable change in the new variant is the removal of a language check that previously blocked infections on Macs with Russian as the default system language. This adjustment hints that the threat actors may be expanding their target base. The malware’s use of advanced techniques, such as the string encryption inspired by Apple’s XProtect, showcases the growing sophistication of modern malware campaigns. These developments indicate that macOS, like all operating systems, remains vulnerable to these evolving cyber threats.

Reference:
  • New Banshee Stealer Variant Targets macOS with Advanced Evasion Tactics
Tags: Cyber AlertsCyber Alerts 2025CyberattackCybersecurityJanuary 2025
ADVERTISEMENT

Related Posts

DevOps Servers Hit By JINX0132 Crypto Mine

Fake FB Ban Fix Extension Steals Accounts

June 3, 2025
DevOps Servers Hit By JINX0132 Crypto Mine

Actively Exploited Chrome V8 Flaw Patched

June 3, 2025
DevOps Servers Hit By JINX0132 Crypto Mine

DevOps Servers Hit By JINX0132 Crypto Mine

June 3, 2025
Linux Core Dump Flaws Risk Password Leaks

Linux Core Dump Flaws Risk Password Leaks

June 2, 2025
Linux Core Dump Flaws Risk Password Leaks

GitHub Code Flaw Replicated By AI Models

June 2, 2025
Linux Core Dump Flaws Risk Password Leaks

Google Script Used In New Phishing Scams

June 2, 2025

Latest Alerts

Fake FB Ban Fix Extension Steals Accounts

Actively Exploited Chrome V8 Flaw Patched

DevOps Servers Hit By JINX0132 Crypto Mine

Linux Core Dump Flaws Risk Password Leaks

GitHub Code Flaw Replicated By AI Models

Google Script Used In New Phishing Scams

Subscribe to our newsletter

    Latest Incidents

    Cartier Data Breach Exposes Client Info

    White House Chief of Staff’s Phone Hacked

    The North Face Hit By 4th Credential Hack

    Covenant Health Cyberattack Shuts Hospitals

    Moscow DDoS Attack Cuts Internet For Days

    Puerto Rico’s Justice Department Cyberattack

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial