Skip to main content

Digital Trends may earn a commission when you buy through links on our site. Why trust us?

This MacOS Trojan stealthily lifts your data, says Microsoft

You might think that your Mac is invulnerable to viruses and other security threats, but you might want to think again. As part of its commitment to intelligence sharing and collaboration, Microsoft recently exposed the evolution of a MacOS Trojan that can stealthily lift your personal data.

First spotted in September 2020, Microsoft says this piece of malware, known as UpdateAgent,  has increasingly progressed to “sophisticated capabilities.” Though it also indicated that the latest two versions are still more “refined,” Microsoft does warn that the malware is again being developed, and more updates could come soon.

MacBook on a chair with the TV app on the screen.
Image used with permission by copyright holder

It is so bad, that Microsoft believes this malware can be leveraged to fetch more dangerous payloads beyond just the adware that it is already injecting into victim machines.

Recommended Videos

But how does it work? Per Microsoft, the UpdateAgent malware can impersonate real software, and then take Mac functionalities under its own control. It is usually first installed to victim Macs by automated downloads without a user’s consent, or advertisement pop-ups, which impersonate video applications and support agents. UpdateAgent can even bypass Gatekeeper, which usually makes sure that only trusted apps can run on Macs. The Malware then takes over a machine and performs malicious acts like injecting adware.

Microsoft worked with Amazon Web Services to pull the URLs used by UpdateAgent to inject adware, but the UpdateAgent campaign has steadily evolved. It went from basic information stealer in December 2020, to the ability to fetch and deliver .DMG files in February 2021, to being able to fetch and deliver .ZIP files in March 2021.

Later in August, the malware expanded its reconnaissance function to scan and collect System_profile and SPHardwaretype information from victim machines. At its worst point in August, the malware even used permissions and wrote its own code to trick Gatekeeper into thinking it’s not even there.

“UpdateAgent is uniquely characterized by its gradual upgrading of persistence techniques, a key feature that indicates this trojan will likely continue to use more sophisticated techniques in future campaigns,” Microsoft said Microsoft.

Microsoft wasn’t clear which versions of MacOS are impacted by UpdateAgent, but it did have some advice that goes beyond using antivirus software. It pointed to using the Microsoft Edge browser, which can block and scan for malicious websites. Other tips include restricting access to privileged resources, installing apps only from the app store, and running the latest versions of MacOS and other applications.

Arif Bacchus
Arif Bacchus is a native New Yorker and a fan of all things technology. Arif works as a freelance writer at Digital Trends…
WWDC 2025 date confirmed as we wait for iOS 19, macOS 16, watchOS 12 and more
Apple WWDC 2025 logo

Apple has confirmed the date for its annual World Wide Developers Conference (WWDC 2025), where executives from the Cupertino, California-based firm will reveal the next generation of its various software platforms.

WWDC 2025 will take place between June 9 and June 13, with the keynote presentation (which Apple is teasing as a "special event") set to happen on the first day of the conference. Apple has also confirmed that this year's WWDC event will be entirely online and all developers can join for free.

Read more
macOS 16: everything you need to know
macos update everything you need to know craig federighi ventura wwdc 2023

Apple's Worldwide Developers Conference (WWDC 2025) date has been set for June 9, 2025, and the next macOS installment will be one of the main attractions. Excitement is already building for this year's installment thanks to rumors of a major design overhaul for the Mac operating system. This is everything we've heard so far about macOS 16.
When will macOS 16 launch?

In recent years, Apple has developed a neat little schedule for WWDC, announcements, and product releases. As we now know that WWDC will take place on June 9, it's highly likely that macOS 16 will be announced on that day. The keynote will introduce all of the biggest new features, updates, and products, making it the most exciting part of the conference for most of us.

Read more
Latest Apple OS land in beta, these are all the new features to try
Apple OS beta

Apple has taken the wraps off its latest operating systems for beta testing, meaning some exciting new features are available.

The new systems run across Apple devices with the arrival of iOS 18.4, macOS 15.4, watchOS 11.4, iPadOS 18.4, tvOS 18.4, and visionOS 2.4 all now available in RC.

Read more