/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Jamf finds Mac cryptomining malware in pirated copies of Final Cut Pro and warns the power of Apple Silicon Macs is making them popular cryptojacking targets

Update: Apple has now commented on the findings - see the end of the piece.  —  Cybersecurity company Jamf Threat Labs

9to5Mac Ben Lovejoy

Context & Ripple Effects

Mac-focused malware had already adapted to Apple’s new processor architecture: Silver Sparrow included a native M1 variant, while earlier reporting found attackers using signed developer certificates to evade Gatekeeper. Apple’s revocation of certificates tied to Silver Sparrow showed that its platform controls can cut off a known distribution path.

Jamf’s finding ties that security history to pirated creative software, making the performance of Apple Silicon machines an asset attackers seek to monetize rather than merely a platform they support.

First-order effects

  • People installing pirated Final Cut Pro copies risk surrendering their Macs’ processing capacity to cryptomining malware, while Jamf gains a concrete Apple Silicon threat pattern for its security monitoring.
  • Apple Silicon Mac owners using untrusted software face a more direct trade-off between high local performance and exposure to resource-draining malware.

Second-order effects

  • Apple and Mac endpoint-security vendors must contend with malware distributed through copied applications, a channel not addressed simply by focusing on legitimate App Store software.
  • The earlier certificate-revocation response to Silver Sparrow highlights how quickly Apple’s trust controls become consequential when attackers rely on identifiable signing or distribution infrastructure.

Third-order effects

  • If Apple Silicon’s performance continues to attract miners, macOS threats are likely to be judged increasingly by their ability to monetize device compute, not only by data theft or persistence.
  • The pattern reinforces a security market in which hardware transitions prompt attackers to produce platform-native malware and push device-management providers to detect abuse at the endpoint.

The trend: Apple Silicon is expanding the economic appeal of Macs to cryptojacking operators, accelerating the adaptation of macOS malware to native hardware capabilities.

Discussion

  • @thomas_drake1 Thomas Drake on x
    Cryptomining malware — “...there have been increasing incentives for bad actors to use cryptojacking techniques. This is where they get malware onto a significant number of other people's devices in order to mine currency for them as a background process.” https://9to5mac.com/...
  • @jbradley89 Jaron Bradley on x
    Today we released a blog on some malware we've been investigating. Embedding pirated apps with malware is a trick that had great success in the early 2000's and a trick that attackers continue to find success in today. Great writeup from @mattbenyo https://www.jamf.com/...
  • @mattbenyo @mattbenyo on x
    I had a ton of fun going down this rabbit hole shout out to @malwarezoo and @jbradley89 for their work on this https://twitter.com/...
  • @jamfsoftware @jamfsoftware on x
    Check out our latest blog post authored by @mattbenyo on a family of #malware Jamf Threat Labs has been following that resurfaced and has been operating undetected, despite an earlier iteration being a known quantity to the #security community. https://ow.ly/...