← Field Notes · Threats
Mac Malware Grows Up
"Macs don't get viruses" was never quite true. It has become far less true as Apple's install base grew.
For a long stretch of the 2000s and early 2010s, "Macs don't get viruses" was a genuinely defensible piece of folk wisdom, not because macOS was architecturally invulnerable, but because malware authors, like any economic actor, went where the volume was. Windows held the overwhelming majority of desktop market share, and building malware for a small, unusual minority platform was a poor use of criminal effort when the same effort aimed at Windows reached vastly more victims.
That calculation has shifted as Apple's install base grew, and security researchers have tracked a steady rise in Mac-targeted malware over the years since, particularly adware and trojans distributed through fake software installers, cracked applications, and malicious browser extensions rather than the self-propagating worms that defined the Windows threat landscape of the 1990s and 2000s. The Mac threat model has always looked different from the Windows one, and it largely still does, but different is not the same as absent.
One case that drew particular attention among researchers was Silver Sparrow, discovered in early 2021 shortly after Apple released its first Apple Silicon Macs. What made it notable was not primarily its payload, researchers who found it never observed it deliver a final malicious action, but the fact that it had already been compiled to run natively on Apple's brand-new M1 chip, showing that malware authors were tracking Apple's platform transitions closely enough to have working code ready near launch, not years behind it.
macOS does carry real, built-in defenses that raise the cost of a successful attack: Gatekeeper checks that downloaded applications are signed by a known developer before allowing them to run without an explicit override, and XProtect, Apple's own built-in scanner, checks new files against a list of known-malicious signatures Apple maintains and updates. These are meaningfully useful and free, and they are also, structurally, the same kind of tool being discussed throughout this series: a maintained list of known threats, checked against what is actually on the machine.
What built-in platform defenses do not cover is the wider ecosystem question of user choice: software installed outside the App Store, developer tools that need broader system access, and the ordinary human tendency to click through a security warning when a piece of software is wanted badly enough. Mac users who have spent a decade assuming the platform's reputation covers them are, on current evidence, assuming something that has become progressively less true, and a threat landscape that grows in proportion to a platform's popularity is not an exception to how malware economics work. It is the rule, arriving a little later than it did everywhere else.