Interestana
Home/News/macOS Screen Sharing Flaw Abused for Monero Mining
Decrypt3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

macOS Screen Sharing Flaw Abused for Monero Mining

macOS Screen Sharing Flaw Abused for Monero Mining

Cybercriminals are actively exploiting a critical authentication vulnerability within macOS Screen Sharing to gain unauthorized root access on affected systems. This exploit allows attackers to covertly install cryptocurrency mining software, specifically targeting Monero, a privacy-focused digital currency. The Dutch national cybersecurity agency, the NCSC (National Cyber Security Centre), has issued a warning regarding this ongoing threat, highlighting the severity of the compromise. The NCSC's advisory indicates that the attackers leverage a flaw in the authentication mechanism of the Screen Sharing feature, which is built into macOS and allows users to remotely control another Mac. By exploiting this weakness, threat actors can bypass normal security protocols and elevate their privileges to the highest level, known as root access. Once root access is achieved, the attackers have complete control over the compromised machine. This level of access enables them to execute any command, install any software, and modify any file on the system without the user's knowledge or consent. In this particular campaign, the malicious software deployed is designed to mine Monero. Monero (XMR) is chosen for its emphasis on privacy, making it more difficult to trace illicit mining activities compared to other cryptocurrencies. The mining process consumes significant system resources, including CPU and GPU power, which can lead to noticeable performance degradation on the infected Mac. Users may experience slower operation, increased fan noise, and higher energy consumption as their devices are used for the attackers' financial gain. Adding to the concern, public proof-of-concept (PoC) code for this vulnerability has been released. The availability of PoC code significantly lowers the barrier to entry for other malicious actors, potentially leading to a widespread increase in attacks. Security researchers and ethical hackers can use such code to test defenses, but it can also be readily adopted by cybercriminals to automate and scale their operations. The NCSC has not yet disclosed specific details about the exact authentication flaw being exploited, nor has it provided an official CVE (Common Vulnerabilities and Exposures) identifier for the vulnerability. However, the agency's warning underscores the immediate need for macOS users to be vigilant and ensure their systems are protected. While Apple typically releases security updates to patch such vulnerabilities, the timeline for a fix remains unknown. In the interim, users are advised to review their Screen Sharing settings and consider disabling the feature if it is not actively in use. For those who require remote access, implementing stronger authentication methods and network security practices is crucial. The exploitation of built-in macOS features like Screen Sharing for malicious purposes highlights the evolving tactics of cybercriminals and the persistent need for robust cybersecurity measures across all operating systems.

Original source — read the full reporting at the publisher:

Read on Decrypt

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next