Photo of Apple MacBook
© Tada Images/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

A sophisticated new info-swiping malware is targeting devices running MacOS — an operating system long thought to be less vulnerable to the dangers of the cybersphere.

Cybersecurity firm Guardz revealed in a Monday blog post that this novel threat, dubbed “ShadowVault,” can steal data from Apple’s laptops and desktops running MacOS.

Guardz added that ShadowVault was first spotted on the notorious dark web “XSS” forum, a gathering place for cybercriminals. The Guardz team also shed light on the malware’s price — available for $500 per month — and provided insight into the black market for such illicit tools, together with screenshots of seller communications and ads.

“Staying safe in the digital world is an active rather than passive process. ShadowVault is a wake-up call for all macOS users and a reminder that no one is immune from the clutches of determined cybercriminals,” Guardz said.

The Emergence of ‘ShadowVault:’ Malware For Sale

Unlike ordinary malware, ShadowVault has been purpose-built to steal sensitive data from macOS systems, somewhat similar to the CloudMensis malware discovered in 2022.

The malware stealthily operates in the background, collecting valuable data such as login credentials, financial information, and personal data. This silent operation makes it particularly difficult for the users to detect any unusual activities until it’s too late.

The potential damage ShadowVault can inflict on businesses and individual users alike is immense.

The blog post also highlighted how the malware exploits the security vulnerabilities of various browsers — including Google Chrome, Microsoft Edge, and Mozilla Firefox — along with over 50 “plug-in browsers” to extract passwords, cookies, credit cards, wallets, and other critical data.

For a monthly fee of $500, cybercriminals can gain access to this advanced piece of software, a price that could potentially yield a significant return on investment given the extensive damage ShadowVault could inflict on businesses and individuals alike.

Guardz Team is Staying One Step Ahead

To combat this escalating threat, the Guardz Cyber Intelligence Research (CIR) team is leveraging covert operations on the dark web to stay one step ahead, the blog post said.

They first identified ShadowVault in its developing stages through anonymous avatars in the dark web, allowing them to track emerging threats and protect clients. By understanding the architecture and behavior of the malware in its infancy, Guardz could devise more effective countermeasures, they added.

In response to the rising danger, Guardz has deployed powerful, real-time detection capabilities and swift response mechanisms to protect its clients from the potential business and personal implications of threats like ShadowVault.

Security Recommendations

Despite macOS being renowned for its innovation and accessibility, the emergence of ShadowVault proves that even the most secure systems can be vulnerable. For instance, a 2022 write-up by a PhD cybersecurity student showed how he broke into Apple’s software processes.

VPNOverview recommends Apple users conduct regular system updates (ensure your macOS is automatically updated), as new releases often patch security vulnerabilities that can be exploited by malicious software. Additionally, users are advised to be vigilant about their online activity and avoid clicking on suspicious phishing links or downloading files from unverified sources.

We also recommend deploying a strong VPN (virtual private network) to encrypt your data and deter cybercrime. We suggest a comprehensive online safety approach that includes firewalls, antivirus software for Apple devices, and regular backups. Adherence to these fundamental cyberhygiene practices can help you reduce the risks associated with threats like ShadowVault.

Stay up to date with the latest VPN deals and trends by signing up for our newsletter below.

Leave a comment