macOS Malware Banshee Evades Detection Using Apple’s Encryption
- The Banshee malware evaded antivirus detection for over two months by mimicking Apple’s XProtect encryption.
- It targeted software-based crypto wallets and browser credentials as a $3,000 “stealer-as-a-service.”
- The operation ended in November after its source code leaked on underground forums.
- Security expert Patrick Wardle describes the malware’s core theft capabilities as basic.
- Recent macOS versions reportedly block this type of threat by default, reducing risk to users.
Banshee malware used Apple’s encryption method to evade detection for months, targeting crypto wallets before shutting down due to a source code leak. Security experts suggest minimal risk for most Mac users due to recent macOS updates.