logo

Banshee 2.0 Malware Steals Apple's Encryption to Hide on Macs

ID: 602b1efb-206e-57c5-b17f-881da023fede

STIX ID: report--602b1efb-206e-57c5-b17f-881da023fede

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-01-09

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

The report describes Banshee, a macOS infostealer sold on Russian cybercrime marketplaces and distributed via cracked-software GitHub repositories and phishing sites; it steals browser credentials, crypto-wallet extension data, system info and login passwords. A later variant reused the string-encryption algorithm from Apple's XProtect to evade detection by most AV engines for months, was linked to over 26 campaigns, and its source code was eventually leaked, increasing the risk of further spread.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.