macOS Users Beware! Hackers Allegedly Offering Full System Control Malware for Rent

A new concerning threat has emerged in the cybercriminal ecosystem targeting Apple users. A sophisticated macOS malware-as-a-service offering called “iNARi Loader” is being advertised on underground forums.

This high-priced stealer represents an alarming evolution in the growing landscape of macOS-specific malware, combining remote desktop capabilities with advanced data exfiltration techniques.

According to a dark web post observed by Cyber Security News, the threat actor behind iNARi Loader is offering this private macOS stealer with an extensive feature set that surpasses previous iterations of similar malware. 

The malware reportedly includes modular capabilities allowing attackers to deploy various payloads ranging from VNC (Virtual Network Computing) remote access to sophisticated data stealers.

One of the most concerning aspects of iNARi Loader is its ability to bypass password prompts, potentially giving attackers unrestricted access to sensitive user data. 

This technique resembles methods used by previous macOS infostealers like Atomic Stealer, which employs fake system prompts to harvest user credentials.

Researchers noted that this represents a significant escalation in macOS-targeted threats. Further, the inclusion of remote desktop functionality gives attackers unprecedented control over compromised systems.

Hackers Offering Malware for Rent

According to dark web advertisements observed by Cyber Security News, the malware can reportedly be delivered through multiple vectors, including terminal commands, disk image files (.dmg), package installers (.pkg), or malicious applications. 

This multi-pronged approach maximizes the attackers’ chances of successfully compromising target systems.

Unlike many competing products that require additional obfuscation, iNARi allegedly doesn’t need crypting services to evade detection, suggesting sophisticated built-in evasion capabilities similar to those observed in other recent macOS malware families.

The threat actor has established a tiered pricing model that reflects the malware’s advanced capabilities:

  • Standard version: $5,000 per month
  • Premium version: $10,000 per month (includes remote desktop protocol access, technical support, and early access to new modules)

These prices significantly exceed those of previous macOS stealers like Atomic ($1,000-$3,000/month) and Banshee ($3,000/month), indicating either exceptional capabilities or targeted marketing toward well-funded threat actors.

The emergence of iNARi Loader continues a troubling trend of increased targeting of macOS systems. 

Throughout 2023 and early 2024, researchers documented multiple new infostealer families, including MacStealer, Pureland, Atomic, RealStealer, MetaStealer, and Banshee.

These malware families typically target sensitive information, including Keychain passwords, browser data, cryptocurrency wallets, and personal files. 

The addition of remote desktop capabilities represents a significant escalation, giving attackers data theft capabilities and persistent control over compromised systems.

Users should remain vigilant against suspicious download prompts, verify software authenticity, enable two-factor authentication on sensitive accounts, and ensure their systems are running the latest security updates. 

Find this News Interesting! Follow us on Google NewsLinkedIn, & X to Get Instant Updates!

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago