Banshee macOS Malware Expands Targeting

Teilen:

The latest version of the Banshee macOS information stealer no longer checks if the infected systems have the Russian language installed.

The Banshee macOS information stealer has been updated to expand its target list to systems using the Russian language, cybersecurity firm Check Point reports.

Banshee was first seen in mid-2024, when it was advertised on cybercrime forums for $3,000 per month, and is believed to have been created by Russian developers.

The malware can collect a wide range of data from macOS systems, including passwords, system information, keychain passwords, browser and browser plugin data, and cryptocurrency wallet information.

In November 2024, the stealer’s source code was leaked online and its developers allegedly shut down their operation as a result, but the malware continues to be distributed via phishing websites and fake GitHub repositories.

According to Check Point, a version of Banshee identified in September that had replaced the original plain text encryption algorithm strings with a string stolen from Apple’s own XProtect antivirus engine remained undetected by antivirus engines until November, when the malware’s source code was leaked.

“This leak not only exposed its inner workings but also led to better detection by antivirus engines. While this leak led to better detection by antivirus engines, it also raised concerns about new variants being developed by other actors,” Check Point notes.

The most significant change observed in the latest version of Banshee, however, is the removal of a Russian language check, which previously prevented the malware from executing on systems using Russian, but now no longer constrains it from targeting specific regions.

Check Point says it “has identified multiple campaigns still distributing the malware through phishing websites. Whether these campaigns are being carried out by previous customers or the author’s private group remains unclear”.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
5:11 am, Juni 23, 2025
Wetter-Symbol 17°C
L: 16° | H: 18°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 75 %
Druck: 1010 mb
Wind: 19 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 40%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
16° | 18°°C 0.2 mm 20% 14 mph 74 % 1016 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
13° | 22°°C 0.2 mm 20% 13 mph 80 % 1016 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
16° | 27°°C 0 mm 0% 9 mph 86 % 1014 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
18° | 26°°C 0.48 mm 48% 14 mph 84 % 1016 mb 0 mm/h
Fr. Juni 27 10:00 pm
Wetter-Symbol
17° | 28°°C 0 mm 0% 16 mph 72 % 1019 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
16° | 17°°C 0.2 mm 20% 13 mph 74 % 1011 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 12 mph 58 % 1013 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
22° | 22°°C 0 mm 0% 12 mph 34 % 1014 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 14 mph 32 % 1014 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
22° | 22°°C 0 mm 0% 13 mph 39 % 1014 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 10 mph 53 % 1016 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
14° | 14°°C 0 mm 0% 8 mph 69 % 1016 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 8 mph 80 % 1015 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€87,980.30
-1.45%
Ethereum(ETH)
€1,942.08
-2.11%
Fesseln(USDT)
€0.87
0.01%
XRP(XRP)
€1.76
-2.67%
Solana(SOL)
€115.41
-2.28%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.132414
-2.14%
Shiba Inu(SHIB)
€0.000010
-2.05%
Pepe(PEPE)
€0.000008
-4.56%
Peanut das Eichhörnchen(PNUT)
€0.218896
13.10%
Nach oben scrollen