CRYPTO

macOS Flaw Lets Hackers Install Monero Miners Remotely

Attackers exploited a macOS Screen Sharing vulnerability to gain full system access and install cryptocurrency miners. Proof-of-concept code is now public.

Researchers at the Dutch cyber agency have documented attacks that use a flaw in macOS Screen Sharing to break into computers and install Monero miners. Monero is a privacy-focused cryptocurrency designed to be harder to trace than Bitcoin. The attackers used the vulnerability to gain root access, the highest level of control on a Mac. Public code that demonstrates how to exploit the flaw has begun circulating, making similar attacks easier to carry out.

Screen Sharing is a built-in macOS tool that lets users control their computer remotely. It works through a network connection and normally requires authentication, meaning the user being connected to must approve the session. The flaw bypasses this requirement. An attacker who finds a vulnerable Mac can gain remote access without being seen or approved. Once inside, they have full administrative control over the machine.

Monero mining uses a computer's processing power to solve mathematical puzzles and validate transactions on the Monero blockchain, a distributed ledger that records all Monero transfers. In return, miners earn newly created Monero coins. When hackers install miners on compromised computers, they get the rewards while the computer's owner pays the electricity bill and bears the wear on their hardware. The attack is silent. The owner may notice their Mac running slowly or their fan running constantly without understanding why.

The vulnerability affects the authentication mechanism that protects Screen Sharing, a core feature of macOS. Once proof-of-concept code spreads, attackers don't need deep technical knowledge to try the exploit. They can target any Mac running a vulnerable version of the operating system. Organizations and individuals using macOS should treat this as a priority if they have not already applied available security updates.

The Dutch agency's public disclosure means Apple is likely already aware of the issue, though confirmation of a patch or timeline for one is not yet clear from the reporting. Victims of such attacks typically won't know they've been compromised unless they check their system's resource usage or notice unusual activity. Regular software updates and disabling remote access tools when not needed are the most practical defenses available to users right now.

Reported by Decrypt - Read the original report.

MORE IN WEB3

← ALL ARTICLES & NEWS