Say Hello to Mac Malware
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
macOS malware is growing as Macs become more common in enterprise environments. Threat actors are adapting their techniques to bypass Apple's built-in security features like Gatekeeper and the Transparency Consent and Control (TCC) framework. Key trends include: malware authors using cron jobs to evade Background Task Management (BTM) detection, replacing legitimate app icons with malware, and porting Windows/Linux malware to macOS. On the defensive side, macOS 15.4 now exposes TCC permission changes to third-party security tools via endpoint security events (ES_EVENT_TYPE_NOTIFY_TCC_MODIFY), and Gatekeeper has been tightened to remove the easy 'right-click to open anyway' bypass. Infostealers like Poseidon are abusing AppleScript to mimic native prompts and steal credentials. The post is a recap of a Huntress Tradecraft Tuesday webinar featuring macOS security researchers.