Hackers exploited macOS Screen Sharing flaw to install Monero miners, Dutch cyber agency says

Абстракт:Attackers exploited a critical Apple Screen Sharing vulnerability to take control of internet-exposed Macs and install Monero mining software, according to the Netherlands‘ National Cyber Security Centre. Apple patched the flaw on Aug. 6, but unupdated machines remain vulnerable; Huntress identified tens of thousands of potentially exposed hosts, many rented from hosting providers. The bug, which bypasses authentication, was rated 9.8 out of 10 by U.S. officials. Monero is a favored target for cryptojacking because it can be mined on ordinary computers and offers private transactions, though payouts per machine are small. The flaw hasn’t yet been added to the federal catalog of actively exploited vulnerabilities.

Quick Take

  • Attackers took advantage of a vulnerability in Apple‘s screen sharing feature to install Monero miners on multiple Macs reachable from the internet, according to a report from the Netherlands’ National Cyber Security Centre.
  • Apple released an Aug. 6 update fixing the flaw, but Macs that havent yet updated are still vulnerable.
  • Security firm Huntress said tens of thousands of Macs were potentially exposed, many of them machines rented by the hour from hosting companies.
  • U.S. officials rated the severity of the vulnerability a critical 9.8/10 on the CVSS scale.

Attackers have been taking over Macs through a flaw in Apple's screen sharing feature and using them to mine Monero, the Netherlands' National Cyber Security Centre (NCSC) recently said in an updated advisory.

The NCSC said it received a report of attacks on multiple Macs that were reachable through the internet. In each case, the attacker took full control of the machine and installed Monero (XMR) mining software, the Dutch-language advisory states. The agency did not state how many machines were affected, or who was suspected to be behind the attack.

Apple patched the flaw on Aug. 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. The company said an attacker on the network could gain access to a Mac through its Screen Sharing feature without a valid password.

Screen Sharing, which lets users remotely view and control their Mac from another computer, is switched off by default, but is commonly used to access “bare-metal” Apple devices hosted on remote servers. Security firm Huntress, in an analysis of the incident, said the flaw tricks the Mac into treating a stranger's connection as one that has already logged in. Because the flaw occurs before authentication, changing or deleting screen sharing passwords does not help.

“Anybody who leverages Apple's Screen Sharing functionality on any supported macOS version needs to apply the most recent security updates immediately,” Huntress researcher Ryan Dowd wrote. Dowd also said he identified “tens of thousands of potentially vulnerable hosts” through a Censys search.

Federal cybersecurity agency CISA initially rated the flaw 7.1 out of 10 the day Apple shipped the fix, then replaced that on Friday with a 9.8, near the top of the 10-point scale, according to the record in the National Vulnerability Database. The flaw has not yet been added to the federal catalog of vulnerabilities known to be under attack.

Why Monero?

Monero has been a target of so-called “cryptojacking,” where mining software is run on hijacked computers, for years given the token's ability to be mined on ordinary computers rather than specialized mining rigs and the private nature of its transactions.

The payoff per machine is thin, however. The entire Monero network issues about 432 XMR a day, worth roughly $179,000 at Sunday's price, split among everyone mining it.

XMR traded at $415.82 on Sunday, up about 3.7% over the past 24 hours, according to The Block's Monero Price page.

Hijacked computing power has surfaced elsewhere this year. In March, an Alibaba-affiliated AI agent called ROME diverted GPUs from its own training runs to mine crypto, according to a technical paper from the teams that built it.

Apple and the NCSC did not immediately respond to The Block's requests for comment.

Отказ от ответственности

Мнения в этой статье отражают только личное мнение автора и не являются советом по инвестированию для этой платформы. Эта платформа не гарантирует точность, полноту и актуальность информации о статье, а также не несет ответственности за любые убытки, вызванные использованием или надежностью информации о статье.
Предыдущая статья

Galaxy снижает вероятность принятия Закона CLARITY до 10%

Следущая статья

HTX открывает празднование 13-летия с призовым фондом $1 млн