AV-Comparatives - Mac Security Test & Review May 2026
#1
Bug 
Quote:Introduction

macOS has long enjoyed a reputation for robust security and is often seen as a “hardened” alternative to Windows. Although malware targeting macOS remains far less common than on Windows and Android, there have still been numerous real-world instances (https://www.macworld.com/article/672879/...flaws.html). In fact, attackers no longer regard Macs as secondary targets (https://www.macworld.com/article/670537/...virus.html, https://objective-see.org/blog/blog_0x84.html). In 2023 and 2024, a surge of sophisticated information-stealers, most notably Atomic Stealer (AMOS) and its forks such as Odyssey (formerly Poseidon), CloudChat, and Shamos, dominated new macOS threats. These cloud-controlled services harvest browser cookies, saved passwords, Keychain data, cryptocurrency wallet credentials, and even extract logins from popular password managers, VPN configurations, and FTP clients. By late 2025, additional stealer families had emerged, including Phexia, DigitStealer, and MacSync Stealer. The latter is notable for being distributed via signed and notarised executables to bypass Gatekeeper scrutiny. Malware in this category is also becoming increasingly modular, with stealers and backdoor components bundled together to enable persistent access rather than one-off data theft.

Distribution tactics have evolved accordingly, with threat actors now relying more on targeted malvertising campaigns and social-engineering schemes rather than user-installed adware bundles. Examples include cloned download sites offering “popular” Mac apps that instead serve up malicious disk images, deceptive Google ads, fake utilities (e.g., video-chat tools, VPN clients), trojanised installers, phishing emails embedding PDF-masquerading apps, and ClickFix-style attacks, which convince users into copy-pasting malicious commands directly into Terminal (https://www.microsoft.com/en-us/security...ostealers/), bypassing Gatekeeper entirely. Consequently, both everyday users and enterprises must supplement basic vigilance with multi-layered defences: modern endpoint protection with real-time malware scanning, DNS and web filtering to block malicious ads, and EDR solutions to detect abnormal system behaviours before data is lost.

Full Report
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Microsoft Edge 149.0.4022.80
Release Summary ...harlan4096 — 15:38
AdGuard VPN for Windows 2.9.4
AdGuard VPN for Wi...harlan4096 — 08:24
Mozilla Firefox Browser 152.0.1
Mozilla Firefox Br...harlan4096 — 06:28
K-Lite Codec Pack 19.8.2 / 19.8.2 Update
Changes in 19.8.2:...harlan4096 — 06:26
HandBrake finally scales better on AMD T...
AMD fixes HandBrak...harlan4096 — 06:24

[-]
Birthdays
Today's Birthdays
avatar (40)storoBox
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu

[-]
Online Staff
There are no staff members currently online.

>