Skip to main content

Malware found on some new Apple M1 Macs mystifies experts

Hackers appear to have wasted little time in targeting Apple’s recently launched Mac computers featuring its new M1 chip.

Colorado-based security firm Red Canary says it has discovered malware on nearly 30,000 Mac computers globally, though experts are currently trying to work out its precise purpose.

Recommended Videos

The malware, dubbed “Silver Sparrow,” is described as a “previously undetected strain,” though another version of it had Intel-made equipment in its sights, according to Red Canary.

According to Arstechnica, researchers have discovered that the mysterious malware is set up to check a control server once an hour. It does this to determine if there are any new commands for the malware to run. But up to now, no commands or payloads appear to have been delivered to the infected computers, leaving experts wondering what may be coming down the track.

The malicious software also incorporates a self-destruct capability that, if and when directed, enables it to remove itself from a computer.

Red Canary says that according to data provided by California-based security firm Malwarebytes, Silver Sparrow had infected 29,139 Mac computers in 153 countries as of February 17, with cases mainly concentrated in the U.S., Canada, U.K., France, and Germany.

Given what it currently knows, Red Canary says the malware presents a “reasonably serious threat” to infected Mac computers.

“Though we haven’t observed Silver Sparrow delivering additional malicious payloads yet, its forward-looking M1 chip compatibility, global reach, relatively high infection rate, and operational maturity suggest Silver Sparrow is a reasonably serious threat, uniquely positioned to deliver a potentially impactful payload at a moment’s notice,” Red Canary said in a blog post detailing what it knows so far about the malware.

It added: “The ultimate goal of this malware is a mystery. We have no way of knowing with certainty what payload would be distributed by the malware, if a payload has already been delivered and removed, or if the adversary has a future timeline for distribution. Based on data shared with us by Malwarebytes, the nearly 30,000 affected hosts have not downloaded what would be the next or final payload.”

The company’s post shares details about how it was able to detect Silver Sparrow using checks that can also uncover other MacOS threats.

Many people may still be of the belief that Apple-made computers don’t get malware. This, of course, isn’t true, and so Mac owners should be certain they have the proper protections in place to ensure their machines have the best chance of keeping hackers at bay.

UPDATE: Apple has reportedly taken steps to prevent additional Mac computers from being infected with the malware.

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Apple’s next-gen M4 Macs look set to embrace serious gaming
The Mac mini on a wooden table.

Apple’s Mac machines and gaming don’t quite fit in the same equation, even though the recent trajectory of its Metal architecture has pulled off a few surprises. But it looks like the upcoming M4-tier machines won’t pull any punches, including the Mac mini.

In the latest edition of his Power On newsletter, Bloomberg’s Mark Gurman writes that for the first time, Apple’s entry-level desktop computer will offer ray tracing support. For the unaware, it’s a lighting system that adds a whole new level of visual realism to games.

Read more
Apple will pay up to $1M to anyone who hacks its AI cloud
Apple's Craig Federighi speaking about macOS security at WWDC 2022.

Apple just made an announcement that shows it means business when it comes to keeping Apple Intelligence secure. The company is offering a massive bug bounty of up to $1 million to anyone who is able to hack its AI cloud, referred to as Private Cloud Compute (PCC). These servers will take over Apple Intelligence tasks when the on-device AI capabilities just aren't good enough -- but there are downsides, which is why Apple's bug-squashing mission seems like a good idea.

As per a recent Apple Security blog post, Apple has created a virtual research environment and opened the doors to the public to let everyone take a peek at the code and judge its security. The PCC was initially only available to a group of security researchers and auditors, but now, anyone can take a shot at trying to hack Apple's AI cloud.

Read more
The M4 Mac launch is incoming, but not how you might expect
The 14-inch MacBook Pro with M3 Max chip seen from behind.

The past few months have been full of speculation, anticipation, and pretty wild rumors concerning the upcoming M4 Macs -- and now the predicted release date of November 1 is just a week or so away. Despite the lack of an event announcement, Bloomberg's Mark Gurman still believes the launch is "imminent," with an announcement reportedly coming on October 30.

According to him, Apple Stores are running very low on iMac, Mac mini, MacBook Pro, Magic Keyboard, Magic Mouse, and Magic Trackpad units -- and this usually happens when updates are about to be released.

Read more