macOS Screen Sharing flaw used to mine Monero
Attackers exploit a macOS Screen Sharing flaw to install Monero miners that run at high CPU and persist across reboots on affected Macs.
Security researchers and incident responders report that attackers are exploiting a flaw in macOS Screen Sharing to install Monero cryptocurrency miners on affected Macs. Investigators began seeing the activity in recent weeks after multiple organizations reported unexplained high CPU use and persistent unknown binaries.
The attacks target Macs with Screen Sharing enabled and unpatched vulnerabilities in the service, allowing remote command execution without interaction from the logged-in user. Once access is gained, attackers download a compact Monero miner, install it under innocuous filenames, register it with LaunchAgents or LaunchDaemons for persistence, and configure it to run with elevated CPU priority.
Analysis of compromised systems shows a consistent pattern: external scanning identifies machines exposing Screen Sharing over the VNC protocol on port 5900, the attacker exploits the flaw to gain remote control, and then fetches the miner binary from remote servers. Network traffic from infected Macs included connections to Monero mining pools and to infrastructure used to update or replace the miner.
The infections appear opportunistic and financially motivated, affecting both home and corporate environments where Screen Sharing was left enabled or where remote management tools were misconfigured. Investigators found no evidence of additional payloads such as ransomware or data-exfiltration tools in the incidents they reviewed.
Because the attack abuses a native macOS service rather than a third-party app, some endpoint signatures missed samples. Detection has relied on behavioral indicators: sustained high CPU load, unusual child processes spawned by Screen Sharing, sudden launches of binaries in temporary folders, and persistent outbound connections to known mining pools. Operators used modest evasion tactics including stripped binaries, distributed hosting, rotated pool addresses and scripts that removed system logs or obscured installation paths.
A security researcher who reviewed multiple incident reports noted, ‘Attackers are scanning for publicly reachable Screen Sharing endpoints, then dropping lightweight miners that run continuously in the background.’
Researchers advising on containment recommend disabling Screen Sharing when not needed, applying the latest macOS updates, restricting Screen Sharing access to trusted networks or VPNs, and scanning endpoints for signs of mining activity. Users can check Activity Monitor for consistently high CPU processes, inspect ~/Library/LaunchAgents and /Library/LaunchDaemons for recently modified entries, and review outgoing connections for traffic to known mining pools.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








