Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

allan.nyholm

macrumors 68020
Original poster
Nov 22, 2007
2,327
2,603
Aalborg, Denmark
Hi everyone
Last night I was looking over a few security measures and updating XProCheck from https://eclecticlight.co/

Was struck me was that Adload malware was operating. Yet, not MalwareBytes nor, CleanMyMac(don't judge me) couldn't find nor remove the actual malware plugin that was being blocked by Apple's own MRT.

Then I actually reinstalled macOS Sequoia 15.4.1 and found that now there's no AdLoad malware, yes OSX Pirrit is being blocked.. I'm really trying hard to locate the culprit.

I check with XProCheck before installing either app mentioned (MalwareBytes and CleanMyMac from setapp - which I also subscribed to because of a slight promise to find and delete malware with CleanMyMac)

Usually I'm not for installing MalwareBytes or such. But, I was getting frustrated because I had a good macOS session and install going. Starting over is a pain each time.

So, XProCheck tells me that the OSX Pirrit malware has been blocked.

Apps that I have installed are all from clean websites. Firefox from mozilla.com, Sketch(beta) from bohemiancoding's website, Discord from Discord.com and Spotify from spotify.com - I have then only installed App Store apps. Apps from Affinity and Xcode from Apple..

I mean, what is going on. I should probably clear Safari cache next.
 

Attachments

  • Screenshot 2025-04-20 at 14.09.45 Large.jpeg
    Screenshot 2025-04-20 at 14.09.45 Large.jpeg
    205.7 KB · Views: 43
Last edited:
See the Technical information section in XProCheckHelp.rtf file included with XProCheck. Lines flagged with a ⚠️ are warnings, not necessarily detections of malware, and seem to be the default when XProCheck can't categorize a line in the log in any other way. I don't know what PluginCanceled means, but my guess is that the scan for Pirrit was terminated by XProtect for some reason (maybe it was taking too long).
 
XProtect is mostly useful to malware authors. When Apple updates XProtect, malware creators find out that their particular version has been discovered and quickly make small changes to bypass it.
In one example, adding spaces to a script it’s all it takes to fool XProtect.
38:43 in the video

More recently “Undetected for over two months, Banshee’s latest version introduced string encryption taken from Apple’s XProtect, likely causing antivirus detection systems to overlook the malware”
https://blog.checkpoint.com/research/cracking-the-code-how-banshee-stealer-targets-macos-users/
https://www.kaspersky.com/blog/banshee-stealer-targets-macos-users/52933/
 
  • Like
Reactions: allan.nyholm
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.