惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Jina AI
Jina AI
博客园 - 司徒正美
大猫的无限游戏
大猫的无限游戏
博客园 - 三生石上(FineUI控件)
J
Java Code Geeks
博客园 - 聂微东
酷 壳 – CoolShell
酷 壳 – CoolShell
爱范儿
爱范儿
美团技术团队
腾讯CDC
博客园 - Franky
MyScale Blog
MyScale Blog
人人都是产品经理
人人都是产品经理
罗磊的独立博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
aimingoo的专栏
aimingoo的专栏
博客园_首页
V
V2EX
Martin Fowler
Martin Fowler
T
The Blog of Author Tim Ferriss

9to5Mac

Apple permanently closing three US stores, here’s when [Updated] Apple Arcade just added 4 new ad-free games with these titles now available At least for now, Liquid Glass in Pixelmator Pro remains a Creator Studio exclusive Apple @ Work: How to add an existing Mac to Apple Business Manager without wiping it Hands-on: SkyDex turns your daily weather check into a Pokémon adventure App Store fight continues as Apple and Epic clash over court-ordered stay OpenAI says to update Mac apps including ChatGPT and Codex as security precaution Apple TV in-person ‘experience’ coming later this month in LA New iPhone Fold leaks cover ‘Ultra’ name, launch timing, more Report: Apple tops global smartphone market for first time in Q1 as overall shipments drop Car Keys in Apple Wallet coming soon to major new vehicle brand Apple previews AI, accessibility, and AirPods Pro 3 research for CHI 2026 April 10, 2026 – Apple Store closures, more VSCO report explores how photographers perceive, adopt, and actually use AI XChat, X’s standalone messaging app, launching soon with these features Apple TV has three shows with finales this week, here’s what’s ending iOS 26.4 adds setting to let you change new Liquid Glass effect Hands-on: Satechi’s 3-in-1 Qi2 charger brings 25W of power with a clean Apple aesthetic [Video] iOS 27 adding new ‘Siri’ app to Home Screen: Here are the rumored features Deals: All 15-inch M5 MacBook Air models $150 off, Series 11 $99 off, Nomad leather iPhone 17 cases, more Amazon launches ‘Prime Video Ultra’ with new features, higher price How the Mac changed the way I clear mental clutter YouTube Premium is getting a US price hike of up to $4/month Tribit StormBox Micro 3: My favorite travel speaker just got better and cheaper FBI used iPhone notification data to retrieve deleted Signal messages Adobe’s low-processing camera app expands support to select iPads and the iPhone 17e New Apple TV movie starring Keanu Reeves now available to stream Apple collector showcases 50 years of Mac startup sounds [Video] WhatsApp is bringing Status updates to the top of the Chats tab iOS 26’s Messages app got a big upgrade for an essential feature
Mosyle identifies two new macOS threats invisible to anti...
Arin Waichul · 2026-04-23 · via 9to5Mac

After exclusively sharing details with 9to5Mac last September on ModStealer, a cross-platform infostealer invisible to every major antivirus engine at the time, Mosyle, a leader in Apple device management and security, is back with two more macOS threats that are flying completely under the radar.

In new details again shared with 9to5Mac, the Mosyle Security Research Team says it has identified two previously undetected samples: Phoenix Worm, a cross-platform stager, and ShadeStager, a modular macOS implant built for credential theft. The two aren’t directly connected in how they work, but together show just how sophisticated Mac malware is getting.

The timing here tracks with what the rest of the industry has been seeing. As I previously reported, infostealers and trojans like Atomic Stealer have been the dominant malware story on Mac for the past year, with attackers shifting away from noisy smash and grab attacks toward persistence. Phoenix Worm and ShadeStager are exactly that.

Phoenix Worm, a stealthy stager

Contrary to its name, Pheonix Worm is exactly the stager here. It’s a Golang-based multi-platform malware, built to act as a stager. Stagers are basically lightweight initial payloads that establish persistence and preps for a second wave of attacks. Rather than dropping the full payload up front, it quietly builds a foothold first. There’s many advantages to doing this.

According to Mosyle, Phoenix Worm’s core functionality includes:

  • Establishing communication with a remote command-and-control (C2) server
  • Generating unique identifiers for infected systems
  • Transmitting system data back to attackers
  • Supporting remote upgrades and additional payload execution

Phoenix Worm doesn’t appear to be a standalone threat either, Mosyle told 9to5Mac. Its design strongly suggests it’s part of a broader toolkit, meant to hand off execution to more advanced payloads further down the attack chain.

At the time of analysis, no antivirus engines detected the macOS or Linux variants, with only limited detection on Windows.

ShadeStager, built for credential theft

In fact, ShadeStager seems to have its sights set on developer environments and cloud infrastructure. It specifically guns for:

  • SSH keys and known hosts
  • Cloud credentials from AWS, Azure, and GCP
  • Kubernetes configuration files
  • Git and Docker authentication data
  • Full browser profiles across major browsers

It also runs extensive recon on the host, pulling user and privilege info, OS and hardware details, network configuration, and environment variables tied to cloud and SSH sessions, according to Mosyle. Everything gets structured and exfiltrated over HTTPS, with support for command execution, data exfiltration, and file downloads.

Interestingly, ShadeStager doesn’t include a hardcoded C2 address and portions of the malware’s code was visible to Mosyle researchers without needing to do any additional work to reverse engineer binaries. This strongly suggests that the malware sample was actually still under development at the time of discovery.

TL;DR

Phoenix Worm and ShadeStager aren’t connected, but they’re built on the same model of attack we’re seeing more and more of. One establishes access, the other extracts credentials and cloud tokens, and neither were detected by a single anti-virus engine at the time of discovery.

That’s the direction Mac malware has moved in 2026. Attackers are writing in Go and Rust for cross-platform compatibility, shipping modular payloads that separate initial access from post-exploitation, and configuring C2 infrastructure dynamically so nothing static matches a signature. The easiest example I can point to is Atomic Stealer, what is undoubtedly becoming the most popular and concerning malware family as a whole. It and its varients have been operating this way for sometime, and the approach appears to be showing up across unrelated samples.

Signature-based antivirus is not enough anymore. Behavioral detection and real-time visibility should be baseline for admins and security teams defending macOS environments today.

Indicators of Compromise

For Mac admins looking to add these threats to their security tools, Mosyle has shared the following SHA256 hashes:

  • ShadeStager: 7e8003bee92832b695feb7ae86967e13a859bdac4638fa76586b9202df3d0156
  • Phoenix Worm: 54ef0c8d7e167053b711853057e3680d94a2130e922cf3c717adf7974888cad2

Follow Arin Waichulis: LinkedInThreadsX

Subscribe to the 9to5Mac Security Bite Podcast for biweekly deep dives and interviews with leading Apple security researchers and experts:

Add 9to5Mac as a preferred source on Google Add 9to5Mac as a preferred source on Google

FTC: We use income earning auto affiliate links. More.