A sophisticated evolution of the Banshee Stealer malware has emerged, targeting macOS systems with improved evasion techniques. Initially discovered by Check Point Research in September 2024, this new variant comes after the original malware’s source code leaked in late 2024.
The enhanced version incorporates Apple’s XProtect string encryption algorithm, making it more difficult for antivirus systems to detect. This development poses a significant threat to over 100 million macOS users worldwide.
Key Features and Distribution:
– Distributed through phishing websites and fake GitHub repositories
– Masquerades as popular software (Google Chrome, Telegram, TradingView)
– Removes previous Russian language restrictions
– Originally offered as Malware-as-a-Service for $3,000 monthly
– Targets browsers, cryptocurrency wallets, and specific file types
The malware’s distribution continues through various campaigns, though it’s unclear if these are conducted by previous customers. According to Eli Smadja from Check Point Research, this threat emphasizes that MacOS users face similar risks as other platforms, particularly through social engineering tactics.
Concurrent to this development, other stealer malware families like Nova, Ageo, and Hexon are being distributed through Discord, primarily targeting gaming communities and user credentials. These attacks focus on expanding networks of compromised accounts by exploiting victims’ friend lists.
