Jamf Threat Labs released a report Thursday on a new macOS malware threat that installs and runs crypto-mining software. The malware is attached to pirated copies of Final Cut Pro which are downloaded from unauthorized distribution points on the Internet.
Hacked versions of Final Cut Pro have a crypto-mining tool called XMRig attached. When the software is downloaded and installed, XMRig launches in the background. Jamf reports that only “a handful” of malware protection apps are able to detect hidden installation of XMRig in January.
XMRig itself is often used legitimately by crypto miners, but since it is an open source utility, it is often subject to illegitimate uses like this. With XMRig running in the background, the Mac devotes processing resources to data mining tasks, which affects performance.
Jamf said this malware installation uses i2p to send the mined cryptocurrency to the attacker’s wallet and to download malicious software components to the Mac. The i2p network protocol is designed for privacy; it is encrypted and uses a tunnel used only by the user, the server and anyone else authorized to access it. Like XMRig, i2p has legitimate uses, but when used by malware it increases the difficulty of tracking network activity.
Jamf’s research revealed that the source of the malware started downloading pirated versions of Final Cut Pro in 2019 and that the malware is smart enough to avoid detection by macOS’s Activity Monitor app. If Activity Monitor is running, XMRig stops and restarts when the user exits Activity Monitor.
In a statement, Apple acknowledged the malware and said it has updated macOS’s Xprotect to block “specific variants cited in JAMF research” and ensure the malware “does not bypass Gatekeeper protections.” Apple has enhanced GateKeeper in macOS Ventura to continuously scan apps to make sure they’re properly signed and haven’t been modified, but previous versions of macOS only perform an initial check.
Downloading the pirated application usually involves the use of a torrent client, and since these clients do not apply any quarantine attributes, the downloads bypass macOS Monterey’s validation checks. With macOS Ventura, however, the pirated copy of Final Cut Pro will not pass validation and fail to launch, but the illegitimate installation of XMRig still occurs and background ripping continues.
This malware attack is precisely why Apple wants you to shop on the App Store, where Apple reviews every app to make sure it’s malware-free. Eventually, more third-party security apps will detect this attack and provide protection (Jamf notes that this attack is blocked by its Protect Threat Prevention service). The easiest way to avoid this attack is to simply not use pirated software. The official version of Final Cut Pro costs $300, although there is a 90-day free trial.
Update 4:55 p.m. ET: Added a statement from Apple.



