macOS Vulnerability Weaponized for Monero Mining Campaign
The Dutch National Cyber Security Center warns of active exploitation of a critical macOS Screen Sharing flaw being used to deploy Monero miners on compromised systems.
macOS Vulnerability Weaponized for Monero Mining Campaign
The Netherlands’ National Cyber Security Center (NCSC) has issued a critical warning regarding active, ongoing exploitation of a severe vulnerability in Apple’s macOS Screen Sharing functionality. The campaign targets Macintosh systems that have exposed port 5900, the communication channel used by Screen Sharing, to internet-accessible networks. In each documented case, attackers leveraged the flaw to gain complete root-level access—the highest administrative privilege available on macOS—before deploying Monero cryptocurrency mining software to silently harvest the victim’s computing resources for profit.
Authentication Bypass Enables Root Access
The underlying security flaw, formally tracked as CVE-2026-65400 and assigned a severity rating of 7.1 out of 10, represents a significant authentication bypass vulnerability. Rather than resulting from brute-force password attacks or weak credentials, the vulnerability emerges from faulty state management during the login sequence. This design flaw permits network-based attackers to log in without possessing any valid credentials whatsoever—authentication requests that should be rejected are instead accepted, granting attackers immediate entry. The NCSC’s advisory notes that public proof-of-concept code demonstrating the exploit has already circulated widely, substantially lowering the technical expertise required for potential attackers to conduct similar operations. Apple has since moved to patch the issue across multiple operating system versions: macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, and Tahoe 26.6.1. However, any user who has not applied these updates remains vulnerable, particularly those whose Screen Sharing service is accessible from the public internet.
Monero Remains the Preferred Currency for Cryptojacking
The choice of Monero as the target cryptocurrency reflects a strategic preference among cybercriminals conducting cryptojacking operations. Unlike Bitcoin or Ethereum, which operate on transparent, publicly auditable blockchains where all transactions are visible, Monero is engineered specifically to conceal transaction details and wallet ownership. This privacy-by-design characteristic makes Monero significantly harder to trace, allowing attackers to convert stolen computing power into untraceable income while the compromised system owner absorbs the costs—both in wasted electricity and degraded machine performance. The NCSC advises immediate action: users should apply available patches without delay and, perhaps more importantly, should never expose Screen Sharing to the internet. This campaign arrives amid a steady surge in cryptocurrency-related malware. Bitdefender recently identified pirated copies of “The Odyssey” bundled with Lumma Stealer wallet-draining malware, while other recent incidents have included malicious code distributed through fake CAPTCHA verification pages routed over BNB Chain networks, the SparkKitty operation that hid credential theft code within mobile applications, deceptive “anime girl” wallpapers aimed at Steam gamers, and crypto-stealing code concealed within a compromised Python library. This incident illustrates the persistent security threats facing all cryptocurrency users, underscoring why system maintenance and vigilance remain critical across the entire crypto ecosystem.
Source: Dutch National Cyber Security Center (NCSC), via Decrypt. Not financial advice.