$ techbeacon
CVE & Exploits

Cybercriminals Target macOS Screen Sharing Vulnerability to Secretly Mine Cryptocurrency

Cybercriminals Target macOS Screen Sharing Vulnerability to Secretly Mine Cryptocurrency

Security agencies are warning Apple users of a newly active threat targeting macOS systems. The National Cyber Security Centre (NCSC) of the Netherlands has issued an advisory regarding a critical authentication bypass vulnerability in the macOS Screen Sharing feature. According to the agency, malicious actors are actively exploiting this security flaw to compromise systems and install unauthorized cryptocurrency mining software.

The surge in malicious activity reportedly began shortly after functional exploit code for the vulnerability was published online. In the cybersecurity landscape, the release of public proof-of-concept exploits frequently triggers a race against time, as opportunistic hackers rush to scan the internet for unpatched systems before administrators can apply necessary updates. In this case, the flaw allows remote attackers to bypass standard login requirements and gain unauthorized access to the built-in macOS Screen Sharing service.

Once inside a compromised Mac, the attackers are deploying software designed to mine Monero, a privacy-centric cryptocurrency. This type of cyberattack, known as cryptojacking, turns the victim's hardware into a profit-generating node for the hackers. While cryptomining malware does not typically steal personal files directly, it heavily drains system resources, causing severe performance degradation, overheating, and increased energy consumption for the affected users.

The NCSC’s warning emphasizes the immediate risk posed to organizations and individuals who leave Screen Sharing enabled and exposed to the public internet. Remote desktop and screen-sharing protocols are frequent targets for network intrusion, and an authentication bypass vulnerability effectively removes the primary line of defense protecting these open ports.

To defend against these ongoing attacks, cybersecurity experts recommend that macOS users and network administrators immediately audit their systems. Disabling the Screen Sharing feature when it is not strictly necessary is the most effective immediate safeguard. For environments where remote access is required, securing the connection behind a virtual private network (VPN) and ensuring that all Apple security updates are fully applied can significantly minimize the attack surface.

This campaign highlights a growing trend of threat actors developing and deploying sophisticated malware specifically tailored for macOS. As Mac computers continue to gain market share in corporate environments, they have become increasingly attractive targets for financially motivated cybercriminals looking to exploit system vulnerabilities for illicit resource hijacking.

Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related