Jamf finds Mac cryptomining malware in pirated copies of Final Cut Pro and warns the power of Apple Silicon Macs is making them popular cryptojacking targets
Update: Apple has now commented on the findings - see the end of the piece. — Cybersecurity company Jamf Threat Labs …
Context & Ripple Effects
Mac-focused malware had already adapted to Apple’s new processor architecture: Silver Sparrow included a native M1 variant, while earlier reporting found attackers using signed developer certificates to evade Gatekeeper. Apple’s revocation of certificates tied to Silver Sparrow showed that its platform controls can cut off a known distribution path.
Jamf’s finding ties that security history to pirated creative software, making the performance of Apple Silicon machines an asset attackers seek to monetize rather than merely a platform they support.
First-order effects
- People installing pirated Final Cut Pro copies risk surrendering their Macs’ processing capacity to cryptomining malware, while Jamf gains a concrete Apple Silicon threat pattern for its security monitoring.
- Apple Silicon Mac owners using untrusted software face a more direct trade-off between high local performance and exposure to resource-draining malware.
Second-order effects
- Apple and Mac endpoint-security vendors must contend with malware distributed through copied applications, a channel not addressed simply by focusing on legitimate App Store software.
- The earlier certificate-revocation response to Silver Sparrow highlights how quickly Apple’s trust controls become consequential when attackers rely on identifiable signing or distribution infrastructure.
Third-order effects
- If Apple Silicon’s performance continues to attract miners, macOS threats are likely to be judged increasingly by their ability to monetize device compute, not only by data theft or persistence.
- The pattern reinforces a security market in which hardware transitions prompt attackers to produce platform-native malware and push device-management providers to detect abuse at the endpoint.
The trend: Apple Silicon is expanding the economic appeal of Macs to cryptojacking operators, accelerating the adaptation of macOS malware to native hardware capabilities.