Hey Mac users, phishing hackers are coming for your passwords now

The old chestnut that people should use Macs if they value their security has long since turned into a smashed conker. While more attacks are aimed at Microsoft Windows devices, because size really does matter, that doesn’t mean other operating systems escape attention from threat actors. That includes Linux and, yes, macOS.

The latest research from LayerX Labs is evidence of the fluidity that applies to modern attack campaigns. Researchers found that one particular campaign, initially targeting Windows users and hosted on the Windows.net platform, has switched aim to Mac users because security features in Chrome, Edge and Firefox browsers were making lowlife too hard for them. 

I’m talking phishing attacks, but don’t think you need to be a mug to fall for them. That simply isn’t the case anymore. Just as it isn’t the case that your Mac is somehow a silver bullet against this type of threat. Threat actors are not stupid either; they morph in response to the security landscape, as the LayerX Labs research aptly demonstrates.

Why phishing hackers are attacking Macs

A little history lesson is required at this point to explain how the attackers were thinking.

LayerX observed what it calls a “sophisticated phishing campaign that initially targeted Windows users by masquerading as Microsoft security alerts” for more than a year. I wouldn’t exactly call it sophisticated myself, given that it employed the immediate danger leverage of a “your computer has been compromised, enter your Windows login to continue” warning.

The techniques were, though. The phishing pages were hosted on the open Microsoft Windows.net platform for hosting Azure applications. “[This] made the messages appear legitimate,” LayerX explained, “since they were security warnings (supposedly) by Microsoft,” and from a Windows domain.

Then things changed.

In February, Microsoft rolled out a feature in Edge designed to counter such scareware tactics. Google did the same for Chrome and Mozilla with Firefox. The results were staggering: an immediate 90% drop in the number of Windows-targeted attacks from the threat actors.

LayerX still saw similar malicious pages. The campaign infrastructure was still online. But potential victims weren’t reaching them: the anti-scareware feature had worked.

Evolution of Mac phishing attacks

So, the attackers evolved. The phishing campaign was modified so take aim at unprotected users. Yep, Mac fans, that would be you.

“Within 2 weeks of Microsoft rolling out the new anti-phishing defenses,” LayerX said it started seeing attacks against Mac users. Before this point, it’s important to note, LayerX had not seen attacks on macOS, only Windows.

The attackers tweaked the messaging to appear more legitimate to macOS users and changed the code by leveraging HTTP OS and user agent parameters but continued the same Windows hosting infrastructure.

“In one specific case,” LayerX said, “the victim was a macOS and Safari user working for a LayerX enterprise customer.” The enterprise in question had deployed a Secure Web Gateway defence, but the attack still bypassed it.

“Mac and Safari users are now prime targets,” LayerX warned, a warning that I hope you are all taking seriously. I have reached out to Apple for a statement.

About The Author

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.