Hey Mac users, phishing hackers are coming for your passwords now

The old chestnut that people should use Macs if they value their security has long since turned into a smashed conker. While more attacks are aimed at Microsoft Windows devices, because size really does matter, that doesnโ€™t mean other operating systems escape attention from threat actors. That includes Linux and, yes, macOS.

The latest research from LayerX Labs is evidence of the fluidity that applies to modern attack campaigns. Researchers found that one particular campaign, initially targeting Windows users and hosted on the Windows.net platform, has switched aim to Mac users because security features in Chrome, Edge and Firefox browsers were making lowlife too hard for them.ย 

I’m talking phishing attacks, but donโ€™t think you need to be a mug to fall for them. That simply isnโ€™t the case anymore. Just as it isnโ€™t the case that your Mac is somehow a silver bullet against this type of threat. Threat actors are not stupid either; they morph in response to the security landscape, as the LayerX Labs research aptly demonstrates.

Why phishing hackers are attacking Macs

A little history lesson is required at this point to explain how the attackers were thinking.

LayerX observed what it calls a โ€œsophisticated phishing campaign that initially targeted Windows users by masquerading as Microsoft security alertsโ€ for more than a year. I wouldnโ€™t exactly call it sophisticated myself, given that it employed the immediate danger leverage of a โ€œyour computer has been compromised, enter your Windows login to continueโ€ warning.

The techniques were, though. The phishing pages were hosted on the open Microsoft Windows.net platform for hosting Azure applications. โ€œ[This] made the messages appear legitimate,โ€ LayerX explained, โ€œsince they were security warnings (supposedly) by Microsoft,โ€ and from a Windows domain.

Then things changed.

In February, Microsoft rolled out a feature in Edge designed to counter such scareware tactics. Google did the same for Chrome and Mozilla with Firefox. The results were staggering: an immediate 90% drop in the number of Windows-targeted attacks from the threat actors.

LayerX still saw similar malicious pages. The campaign infrastructure was still online. But potential victims weren’t reaching them: the anti-scareware feature had worked.

Evolution of Mac phishing attacks

So, the attackers evolved. The phishing campaign was modified so take aim at unprotected users. Yep, Mac fans, that would be you.

โ€œWithin 2 weeks of Microsoft rolling out the new anti-phishing defenses,โ€ LayerX said it started seeing attacks against Mac users. Before this point, itโ€™s important to note, LayerX had not seen attacks on macOS, only Windows.

The attackers tweaked the messaging to appear more legitimate to macOS users and changed the code by leveraging HTTP OS and user agent parameters but continued the same Windows hosting infrastructure.

โ€œIn one specific case,โ€ LayerX said, โ€œthe victim was a macOS and Safari user working for a LayerX enterprise customer.โ€ The enterprise in question had deployed a Secure Web Gateway defence, but the attack still bypassed it.

โ€œMac and Safari users are now prime targets,โ€ LayerX warned, a warning that I hope you are all taking seriously. I have reached out to Apple for a statement.

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.