Macs are under attack from this Windows malware — what you need to know

MacBook Pro 16-inch 2021 sitting on a patio table

Infecting Macs with malware often requires cybercriminals to get a bit more crafty, which is why they’re now using a novel approach to infect Apple’s computers with a malware strain previously used to target Windows PCs.

As reported by The Hacker News and discovered by security researchers at Trend Micro, the Dridex banking malware is currently being used to target devices running macOS. However, what sets this campaign apart is the fact that the cybercriminals behind it have figured out a way “to deliver documents with malicious macros to users without having to pretend to be invoices” according to a new report.

Dridex is an information stealer malware attributed to the cybercriminal group Evil Corp that is used to harvest sensitive data from infected machines, but it can also execute malicious modules. In the past, it has been used to target Windows PCs through macro-enabled Microsoft Excel spreadsheets distributed via phishing emails.

Now that Microsoft has blocked macros by default in its office software, the cybercriminals behind this latest campaign have come up with a clever way to enable them on macOS.

Adding malicious macros to existing documents

Microsoft Word

(Image credit: Shutterstock)

The Dridex malware sample that Trend Micro analyzed arrives as a Mach-O file, which is a type of executable used by both macOS and iOS. First discovered back in 2019 and submitted to VirusTotal, 67 more artifacts based on it have been detected in the wild including some as recently as December of last year.

The Mach-O file has a malicious document embedded inside it that was detected all the way back in 2015. However, it incorporates an Auto-Open macro that runs automatically once the document is opened.

If a Mac user downloads the file and opens it, the malicious code within the Mach-O executable overwrites all of the Microsoft Word files in their user directory in macOS. According to Trend Micro, this makes it “more difficult for the user to determine whether the file is malicious since it doesn’t come from an external source”.

From here, the macros in a user’s documents that have been overwritten contact a remote server to download additional files including a Windows executable file (.exe) that can’t even run on macOS. The Dridex malware is also downloaded onto the compromised Mac.

How to stay safe from Mac malware

Malware

(Image credit: solarseven/Shutterstock)

In this case, the malware itself can’t infect targeted Macs since it’s contained within an executable Windows file. However, if a user downloads the Mach-O file and has their own files overwritten with malicious ones, then tries to share them online, they could unwittingly infect their family, friends and coworkers with malware.

Although Apple includes a built-in malware scanner called Gatekeeper and its own XProtect antivirus software with every Mac it sells, you might want to consider picking up one of the best Mac antivirus software solutions for your devices for additional protection.

Macs have historically been safer than Windows PCs, which absolutely need the best antivirus software, but as Apple’s computers have become more popular in recent years, cybercriminals have been devising new ways to target Macs. This is why you need to be careful when downloading new files online, clicking on links in emails and messages or opening attachments from unknown senders.

For now at least, Macs are safe from the Dridex malware — but the cybercriminals behind this campaign could come up with a way to modify it so that it is compatible with macOS.

TOPICS
Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
MacBook Pro 2021 (16-inch) on a patio table
Macs under attack from dangerous malware targeting digital wallets and Apple’s Notes app — how to stay safe
Malware
New macOS malware uses Apple's own code to quietly steal credentials and personal data — how to stay safe
MacBook Pro 2021 (16-inch) on a patio table
Millions of Mac owners urged to be on alert for info-stealing malware
A hacker typing quickly on a keyboard
Hackers are posing as Apple and Google to infect Macs with malware — don’t fall for these fake browser updates
A hacker typing quickly on a keyboard
Thousands of WordPress sites hijacked to spread Windows and Mac malware - how to stay safe
and image of the Google Chrome logo on a laptop
Google Docs under attack from info-stealing malware — how to keep your data and your emails safe
Latest in Malware & Adware
Green skull on smartphone screen.
Over 1 million Android devices infected with password-stealing, pre-installed botnet malware — how to stay safe
Green skull on smartphone screen.
This Android banking trojan steals passwords to take over your accounts — and all it takes is a single text message
PayPal logo on iPhone
Watch out! Scammers are using this PayPal setting to take over your PC
A laptop displaying the Chrome logo
Don't click this — malicious ads impersonating Google Chrome spreading dangerous malware
and image of the Google Chrome logo on a laptop
Google Docs under attack from info-stealing malware — how to keep your data and your emails safe
MacBook Pro 2021 (16-inch) on a patio table
Millions of Mac owners urged to be on alert for info-stealing malware
Latest in News
Former AATIP director Lue Elizondo tells documentary filmmaker Dan Farah we are 'not alone' in new 1hr 49m UFO film "The Age of Disclosure" (2025)
How to watch 'The Age of Disclosure' – can you stream UFO documentary online?
A render of the iPhone 17 Pro Max
iPhone 17 Pro Max — this new rumor could push people towards iPhone 17 Air
Isabela Merced as Dina and Bella Ramsey as Ellie in The Last of Us Season 2
New 'The Last of Us' season 2 trailer shows off my favorite moment from 'Part II'
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #372 (Monday, March 10 2025)
apple watch 4
Apple Watch escapes U.S. import ban after court victory in patent case
samsung galaxy s25 edge mockups at galaxy unpacked 2025
iPhone 17 Air and Samsung Galaxy S25 Edge could get yet another ultra-thin rival