Monero Miners Installed via Exploited Apple Screen Sharing Flaw
Apple's Screen Sharing feature has been exploited by hackers to install Monero miners on Macs, according to an updated advisory from the Netherlands' National Cyber Security Centre (NCSC). The agency received reports of attacks on multiple Macs reachable through the internet, with each attack allowing the attacker to take full control of the machine and install Monero mining software.
The flaw was patched by Apple in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 on August 6th. However, the NCSC warns that changing or deleting Screen Sharing passwords does not prevent the attack.
Ryan Dowd of Huntress analyzed the incident and identified tens of thousands of potentially vulnerable hosts through a Censys search. The Federal cybersecurity agency CISA initially rated the flaw 7.1 out of 10, but later increased it to 9.8 on the National Vulnerability Database.
The attackers are using Monero's ability to be mined on ordinary computers rather than specialized mining rigs and its private transactions, making it a target for 'cryptojacking'. However, the payoff per machine is thin, with the entire Monero network issuing about 432 XMR a day, worth roughly $179,000 at Sunday's price.