Listen to this Post

Introduction: A New Wave of macOS Malware
Apple devices have long been praised for their sleek design and advanced security features, but the growing popularity of Macs has turned them into a lucrative target for cybercriminals. What was once considered a relatively “safe” ecosystem is now being shaken by the emergence of powerful infostealers. After the infamous Atomic macOS Stealer (AMOS) dominated headlines in 2023, a new player is on the rise — Mac.c, a sophisticated malware developed by a threat actor known as “mentalpositive.” This alarming evolution signals that the macOS threat landscape is rapidly shifting, making it critical for both enterprises and individual users to stay alert.
The Growing Threat: Mac.c vs. AMOS
AMOS (Atomic macOS Stealer) became notorious in 2023 for stealing sensitive user data from macOS systems. Security researchers, journalists, and victims alike know its name. But now, Moonlock, the cybersecurity division of MacPaw, has discovered a new adversary — Mac.c, an emerging infostealer gaining traction in underground forums.
The malware’s developer, “mentalpositive,” is believed to be of Russian origin and has been active for only four months. Despite this short period, Mac.c is already competing with established infostealers like AMOS due to its efficiency and unique development style.
Transparency in Malware Development
What makes Mac.c unusual is the developer’s “open-source” mindset. Unlike most cybercriminals who work in secrecy, mentalpositive openly shares progress updates, asks for feedback, and builds malware almost like a software startup. This transparency has attracted attention in the hacker community, and shockingly, it’s working in their favor.
Technical Prowess of Mac.c
Mac.c isn’t just another clone — it’s a streamlined, optimized malware designed for rapid, high-impact data theft. Key features include:
Trimmed binary for faster downloads and fewer detection footprints
Constantly updated command-and-control URLs
Unique builds to bypass Apple’s XProtect security
Support for multiple browsers and phishing modules targeting Trezor seed phrases
The addition of a web-based control panel for customers makes Mac.c even more dangerous. Buyers can generate custom builds, monitor infection stats, and manage campaigns — essentially running cyberattacks with minimal technical knowledge.
A Shifting macOS Threat Landscape
While Windows remains the biggest malware target, macOS is catching up fast. Apple’s global market share hit 17.1% in 2024, with shipments soaring nearly 26% year-on-year. More users mean more victims, and malware developers are ready to capitalize.
Infostealers have now surpassed adware as the leading form of Mac malware, making up over 28% of detected threats, according to Jamf. Their popularity lies in their easy-to-use business model (Malware-as-a-Service) and quick financial returns compared to ransomware.
Protecting Yourself from Infostealers
Apple’s built-in defenses like Gatekeeper and XProtect offer a first line of defense, but users must adopt stronger habits:
Download apps only from trusted sources like the Mac App Store
Double-check links before clicking
Use complex passwords with non-SMS two-factor authentication
Be cautious with app permissions
Regularly update software and macOS
🔎 What Undercode Say:
The rise of Mac.c highlights several alarming cybersecurity trends.
1. Crowdsourced Malware Development
Unlike traditional malware, Mac.c thrives on community-driven feedback. This collaborative model resembles open-source development — but with malicious intent. Such transparency accelerates innovation, making threats evolve faster than defenses.
2. Stealer-as-a-Service Is the Future
Just like subscription-based software, cybercriminals now offer Malware-as-a-Service (MaaS). For a small fee, anyone can purchase tools like Mac.c, generate builds, and launch attacks with little knowledge. This democratization of cybercrime is why infostealers are spreading like wildfire.
3. macOS No Longer a Safe Haven
For years, Mac users believed they were immune compared to Windows users. That myth is now shattered. With Apple’s rising popularity in both consumer and enterprise markets, attackers see a goldmine. Mac.c’s aggressive features show that macOS-specific malware is entering a new era of sophistication.
4. Shift from Ransomware to Infostealers
Ransomware requires negotiation, time, and risk. Infostealers, however, deliver instant rewards by selling stolen credentials, crypto wallets, and personal data. This fast-payout model is far more attractive to cybercriminals.
5. Weakening Trust in Apple’s Ecosystem
If Apple fails to stay ahead of these threats, it risks losing user confidence. Security-conscious businesses may rethink mass adoption if infostealers keep spreading.
✅ Fact Checker Results
Mac.c malware is real and confirmed by Moonlock researchers.
Infostealers have overtaken adware as the most common Mac malware.
Apple’s market share did increase significantly, fueling cybercriminal interest.
🔮 Prediction
Looking ahead, Mac.c is just the beginning. As Apple’s user base expands, we’ll see more modular, service-based malware ecosystems targeting macOS. Future variants may include AI-enhanced attacks capable of adapting in real time. Unless Apple revolutionizes its security model, infostealers could dominate the macOS threat landscape within the next two years.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: 9to5mac.com
Extra Source Hub:
https://www.twitter.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




