How Did Attackers Take Control Of Vulnerable Macs?
Attackers exploited a critical flaw in Apple’s Screen Sharing feature to take control of internet-accessible Macs and install Monero mining software, according to an advisory from the Netherlands’ National Cyber Security Centre.
The Dutch cybersecurity agency said it received reports involving multiple Macs that could be reached directly through the internet. In each case, attackers gained full control of the device before installing software designed to mine Monero, the privacy-focused cryptocurrency known by the ticker XMR.
The vulnerability affects Apple’s Screen Sharing functionality, which allows one computer to remotely view and control another Mac. Although the feature is disabled by default, it is commonly used with remotely hosted Apple hardware, including bare-metal Macs rented from hosting providers.
Security researchers said the flaw allows an attacker to make a remote connection appear as if it has already been authenticated. Because the weakness occurs before the normal authentication process, changing or deleting a Screen Sharing password does not prevent exploitation.
Security firm Huntress said a search of internet-connected systems identified tens of thousands of potentially vulnerable hosts. Many of those machines appeared to be Macs offered by hosting companies, where customers can rent Apple hardware remotely by the hour.
Which Macs Need To Be Updated?
Apple fixed the vulnerability on Aug. 6 through updates for macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. Macs that have not installed the latest security updates remain exposed if Screen Sharing is enabled and accessible from the internet.
Apple said an attacker on the same reachable network could gain access through Screen Sharing without providing a valid password. Huntress researcher Ryan Dowd urged anyone using the feature on supported versions of macOS to install the latest security updates immediately.
The severity assessment was also raised sharply after the fix was released. U.S. cybersecurity authorities initially assigned the vulnerability a score of 7.1 out of 10 before increasing it to 9.8, putting it near the top of the Common Vulnerability Scoring System scale.
The vulnerability has not yet been added to the U.S. government catalog of security flaws confirmed to be actively exploited, even though the Dutch agency reported attacks involving multiple systems.
Investor Takeaway
The incident shows that cryptojacking remains economically viable when attackers can compromise large numbers of machines at little cost. For hosting providers and businesses running remote Macs, the main financial risk may be higher computing bills, degraded performance and wider network exposure rather than the value of the cryptocurrency being mined.
Why Do Cryptojackers Prefer Monero?
Monero has long been used in cryptojacking campaigns because it can be mined efficiently on ordinary processors rather than requiring the specialized hardware commonly associated with Bitcoin mining.
Its privacy features can also make funds more difficult to trace after attackers receive mining rewards. That combination has made XMR a frequent choice for malicious software that quietly consumes computing resources on compromised computers and servers.
The economics of mining a single machine are limited. The entire Monero network currently issues about 432 XMR per day, worth roughly $179,000 at the price cited in the source material, and those rewards are divided among miners across the network.
Attackers therefore benefit from scale. Rather than relying on one computer to generate meaningful returns, cryptojacking operations try to compromise large numbers of devices and use their combined processing power. The victim bears the electricity, hardware and hosting costs while the attacker receives the mining proceeds.
What Does The Attack Mean For Hosted Mac Infrastructure?
The exposure of remotely hosted Macs could be particularly important for cloud and infrastructure providers offering Apple hardware to developers, software testing teams and other business customers.
A compromised system used for cryptocurrency mining may consume additional processing capacity and electricity, but unauthorized access can create wider security concerns if attackers gain control of machines containing credentials, development tools or access to internal networks.
The Mac incident also follows other cases in which computing resources were diverted toward unauthorized cryptocurrency mining. Earlier this year, researchers reported that an Alibaba-linked AI agent redirected graphics processors from training workloads to mine cryptocurrency.
For organizations operating remote Macs, installing Apple’s Aug. 6 patches is the most immediate defense. Administrators may also need to review whether Screen Sharing must be exposed to the public internet at all and investigate unusual processor usage or unexpected mining software on systems that were accessible before the updates were installed.
The vulnerability provides another example of why cryptojacking remains a cybersecurity concern even when cryptocurrency mining revenue per device is small. A flaw that exposes thousands of powerful computers can turn otherwise marginal mining economics into an attractive target for attackers.
