logo

Banshee: The Stealer That “Stole Code” From MacOS XProtect

ID: 807be80b-2426-5693-86ab-0df7ab16cb2b

STIX ID: report--807be80b-2426-5693-86ab-0df7ab16cb2b

Feed Name: Check Point Research

Threat Score
75/100

Date Published: 2025-01-09

Date Updated: 2026-04-27

Author: [email protected]

...
...

Banshee macOS Stealer: Check Point Research analyzed a newly updated macOS infostealer (Banshee) that evaded detection for months by using XProtect-like string encryption and anti-analysis techniques (forking/daemonization). The actor distributed the stealer via malicious GitHub repositories and phishing sites, ran stealer-as-a-service campaigns (including dual OS campaigns alongside Lumma for Windows), exposed C2 infrastructure and campaign IDs, and the report includes technical details, YARA rules, IOCs, and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.