Malware for macOS Uses Windows EXE Files to Evade Detection, Install Adware

Advertisement
By Jamshed Avari | Updated: 13 February 2019 17:23 IST
Highlights
  • macOS does not check Windows EXE files which usually cannot be executed
  • The malware uses the Mono cross-platform framework to run EXE files
  • Adware is downloaded and installed automatically when the EXE is run

Trend Micro Security has discovered a new form of malware that targets macOS but masquerades as a Windows executable file. This allows it to evade detection by Apple's own Gatekeeper security tool, since Windows EXE files are typically disregarded because of their inability to run. The malware, however, does execute these files using a software framework called Mono which is designed to enable cross-platform app development. The malware has been found in pirated versions of popular Mac apps that are being distributed as Torrents. Once installed, it contacts a remote server, reports your system information, and downloads whatever additional malware the author wants to send.

The threat, which does not have a specific name, has been confirmed by Trend Micro to have struck Macs in the US, UK, Australia, South Africa, and Europe. It is not believed to have been specifically targeted at any region or type of user.

Researchers have found this malware being distributed as several commonly pirated macOS apps including Little Snitch, a firewall; the Traktor Pro 2 DJ software; Paragon NTFS, which is widely used to access hard drives formatted for Windows; and Wondershare's Filmora video editing suite.

Advertisement

The malware cleverly includes the Mono framework within the downloaded package. Users would otherwise have to have Mono installed already, which would significantly reduce this malware's ability to infect Macs. Interestingly, the malicious EXE files will not run on Windows because they are specifically designed to infect Macs.

Advertisement

After being installed successfully, the malware sends identifying system information including the serial number of the infected Mac and its hardware and software configuration to a remote server. It is not clear what this information is used for. Trend Micro analysed a sample and found that it also downloaded and automatically executed three files including what appeared to be an installer for Adobe Flash but was actually adware. Thus, the malicious EXE file can be used to infiltrate other potentially more serious types of malware onto an infected PC including adware or ransomware.

The Mono framework is an implementation of Microsoft's .NET software development environment, and is developed and maintained by Microsoft subsidiary Xamarin. It allows Windows developers to map DLL file dependencies to alternatives in other host OS environments including macOS, Android, iOS, multiple Linux distributions, and even some embedded operating systems such as the ones used by popular game consoles.

Advertisement

Gatekeeper is Apple's attempt to prevent users from harming their machines by screening executable files for potential threats. It can also be set to prevent users from installing apps from anywhere other than its own App Store, commonly referred to as a “walled garden” approach to security. Gatekeeper typically checks an app publisher's code signatures and verify the integrity of downloaded files.

In 2015, security researchers discovered that the macOS Gatekeeper could be bypassed simply by using an already trusted file to load other files from arbitrary folders. Mac users (and all PC users) are advised to be very careful about where they download software from.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 16 Could Feature Same Cameras as the Rumoured Oppo Find N6
  2. Samsung Galaxy S26, Galaxy S26 Ultra Spotted in Leaked Hands-On Images
  3. Samsung Galaxy S26 Ultra Tipped to Launch With These Camera Improvements
  4. Xiaomi 17 Series May Be Expanded With Fifth Model Featuring Snapdragon Chip
  5. Oppo Find N6 Launch Timeline, Key Specifications Tipped Ahead of Launch
  6. Redmi Pad 2 Pro 5G Price Range, Chipset Revealed Ahead of Launch in India
  7. Amazon Get Fit Days Sale 2026 Announced in India: See Top Deals, Discounts
  8. iQOO Z11 Turbo Confirmed to Launch in These Four Colourways in China
  9. NASA to Preview Upcoming ISS Spacewalks Focused on Solar Array Upgrades in January 2026
  10. New Study Explains Why Earth's Poles Are Heating Up at an Alarming Rate
  1. TCL Note A1 Nxtpaper E-Note Launched With 8,000mAh Battery, 11.5-Inch Display: Price, Specifications
  2. Samsung Partners With Nota AI to Enable Advanced On-Device AI on Exynos 2600 Chip
  3. Japan’s H3 Rocket Suffers Setback as Michibiki 5 Navigation Satellite Launch Fails
  4. OnePlus 16 Tipped to Feature Same Camera Hardware as Oppo Find N6; May Get 200-Megapixel Camera
  5. NASA to Preview Upcoming ISS Spacewalks Focused on Solar Array Upgrades in January 2026
  6. New Study Explains Why Earth’s Poles Are Heating Up at an Alarming Rate
  7. Kumki 2 OTT Release Date: When and Where to Watch This Tamil Movie Online?
  8. The Demon Hunter OTT Release Date: When and Where to Watch it Online?
  9. A Legacy of Mettle: The Bharat Benz Story Now Streaming Online: Know Where to Watch it Online
  10. Members Only: Palm Beach Season 1 Streaming on Netflix: Everything You Need to Know About This Show
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.