Apple Updates macOS to Detect Malware Disguised in Windows EXE Files

Advertisement
By Jamshed Avari | Updated: 25 April 2019 14:46 IST
Highlights
  • MacOS malware was detected spreading through Windows files in February
  • Cross-platform frameworks such as Mono made this possible
  • Apple has made the updates without a big announcement

Apple has reportedly updated the macOS XProtect anti-malware framework to protect Macs against an innovative type of attack carried out using cross-platform Windows executable files. Usually considered harmless because they can't run on macOS, Windows EXE files have recently been used because of the emergence of cross-platform software frameworks, particularly one called Mono, which can be used to run EXE files created specifically for it. The unnamed malware, first reported in February this year, bundled such seemingly innocuous files with pirated copies of popular Mac apps, and included the Mono framework to ensure that they would be able to run on Macs. Infected Macs then sent personally identifying information to a remote server and had even more malware sent to them including advertising spam.

The threat was first reported by Trend Micro, after the security firm detected such infections in the US, UK, Europe, Australia, and South Africa. Now, Apple appears to have updated XProtect, which works in conjunction with the Gatekeeper and File Quarantine tools, to detect and such executables and prevent them from causing harm. 

Bleeping Computer reports that macOS security expert Patrick Wardle has tweeted a screenshot and information about two new rules added to XProtect on April 19, which specifically protect against Windows executables. Wardle explained his findings in a Twitch live stream on Tuesday and has said that he will soon make the video available on his YouTube channel.

Advertisement

The Mono framework is an implementation of Microsoft's .NET software development environment, and is developed and maintained by Microsoft subsidiary Xamarin. It allows Windows developers to map DLL file dependencies to alternatives in other host OS environments including macOS, Android, iOS, multiple Linux distributions, and even some embedded operating systems such as the ones used by popular game consoles.

Advertisement

Apple appears to have taken this threat very seriously. Many users might have been taken in assuming that Windows files cannot cause any trouble on Macs, but this is no longer true thanks to tools like the Mono Framework, which are going to become more popular over time.  Users should now see familiar macOS Gatekeeper warnings when suspicious EXE files are detected or when a user tries to run them. The rules include the names of known adware.

The XProtect updates were released without any announcement from Apple. It does not have any visible interface in macOS, but it ties into File Quarantine, which confirms whether a user wants to run files downloaded from the Internet and shows the user when they were downloaded and through which application. If the file contains known malware, File Quarantine will warn users that it will harm their computers. Recent versions of macOS include Gatekeeper, which allows digitally signed files from trusted developers to be allowed to run without throwing up such alerts.  

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi's HyperOS 3 Update Is Rolling Out to These Phones, Tablets
  2. iOS 26.3 May Make It Easier to Switch to an Android Phone
  3. OpenAI Says ChatGPT Will Soon Become an Operating System
  4. Dhruv64: India's First Homegrown 64-Bit Dual-Core Microprocessor Unveiled
  5. Global Smartphone Shipments Will Reportedly Drop in 2026 Due to This Reason
  6. Realme Narzo 90 Series With 7,000mAh Battery Launched in India: See Pricing
  7. Astronomers Watch a Dormant Neutron Star Reignite After a Decade of Silence
  8. Raat Akeli Hai: The Bansal Murders OTT Release Date: When and Where to Watch it Online?
  9. Oppo Find X9 Ultra Battery Capacity Teased By Company Executive
  10. Private Satellites Pinpoint Methane Emissions from Oil, Gas, and Coal Facilities Worldwide
  1. New Orbital Clues Reveal How Hot Jupiters Moved Close to Their Stars
  2. Heartiley Battery Out on OTT: Know Where to Watch This Tamil Sci-Fi Series Online
  3. Raat Akeli Hai: The Bansal Murders OTT Release Date: When and Where to Watch it Online?
  4. Private Satellites Pinpoint Methane Emissions from Oil, Gas, and Coal Facilities Worldwide
  5. Ishq Vishk Rebound Out on OTT: Know Where to Watch This Rohit Saraf Starrer Romcom
  6. Theeyavar Kulai Nadunga Now Streaming Online: Where to Watch This Dark Psychology Thriller
  7. My Lottery Dream Now Available For Streaming Online On This Platform: What You Need to Know
  8. Global Smartphone Shipments to Slightly Shrink in 2026 Due to RAM Shortage, Higher Component Costs: Report
  9. Dead Island 3 Is in Development at Dambuster Studios; Launch Planned for 2028
  10. Google and ChatGPT Remain the Most Popular Services as Internet Traffic Grows by 19 Percent: Cloudflare
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.