Apple's macOS platform found encryption and hijacked malware and distributed it through pirated Final Cut Pro applications.
CTOnews.com On February 24, Jamf Threat Labs reported the discovery of a new cryptojacking malware on macOS, distributed via pirated Final Cut Pro.
During routine surveillance, the team received alerts about XMRig. XMRig is a command-line tool for mining cryptocurrencies, and its functionality is not malicious, but because of the tool's customizable, open-source nature, attackers like to use it to launch attacks.
The team found a malicious version of XMRig in pirated video editing software Final Cut Pro, which once users run Final Cut Pro, runs XMRig in the background disguised as an "mdworker_local" process, hijacking device resources for mining.
XMRig communicates using the Invisible Internet Project (i2p), a dedicated network layer that anonymizes traffic. Malware uses it to download malicious components and send mined currency to the attacker's wallet.
The researchers pointed out that because the malware still retains the original code signature and only modifies the application, it cannot run on macOS Ventura, and there will be a failure of the system security policy.
CTOnews.com with report: Evasive cryptojacking malware targeting macOS found laundering in pirated applications