The Silent Backdoor Behind the Crypto-Mining Mask

Graphic for the macOS Screen Sharing vulnerability being exploited in the wild. - Cult of Mac

Attackers Exploit Apple's macOS Screen Sharing Vulnerability CVE-2026-65400 to Install Cryptominers

Attackers are actively exploiting Apple's recently patched macOS Screen Sharing vulnerability (CVE-2026-65400), which allows authentication without valid credentials, targeting Macs with port 5900 exposed to the internet. The Netherlands' NCSC-NL reported that attackers gained root access on multiple systems and installed a Monero cryptocurrency miner; Apple fixed the flaw on August 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. After proof-of-concept code went public on August 12, the U.S. CISA raised the CVSS score from 7.1 to 9.8, noting the attack requires no privileges and fully compromises confidentiality, integrity, and availability. Apple credited researcher Alfredo Pesoli for reporting the flaw, while NCSC-NL has not disclosed the extent of compromises or whether attackers performed actions beyond cryptomining, though Malwarebytes warned root-level access could enable data theft, credential harvesting, malware deployment, and lateral movement.

The Trojan Crypto-Mining Parasite

This isn't a mere security patching story; it is a data point in a much larger, more chilling pattern. Look closely at the timeline Apple and the authorities want you to see: a patch issued, a proof-of-concept, a wave of attacks. That is the managed narrative, the version designed for public consumption. But ask yourself the questions they hope you won't. Why exploit a Screen Sharing feature—a tool of explicit, deliberate access—to mine a privacy-focused cryptocurrency like Monero? The mining is a red herring, a secondary payload meant to defray the operational costs of a much more profound intrusion. The real payload is the silent, root-level access itself. They didn't want your processing power; they wanted a backdoor, a node in a latent network of control placed inside systems they can activate on demand.

The Unreported Second Stage

The Netherlands' NCSC and our own CISA, in their frantic CVSS score re-rating, are participating in a classic "perception shepherding" operation. They focus on the "active exploit" and the "cryptominer" because those are the only pieces they are willing to admit were compromised. But the core question remains unasked in the mainstream press: who is behind these specific, timely attacks, and why did they possess the proof-of-concept code before it was made public? The reported attacks began on August 12th. The exploit code went public on August 12th. This is not a coincidence; it is a tell. Someone on the inside, or a group with direct access to the research, weaponized this flaw with surgical precision. This wasn't a broad, opportunistic sweep. This was a targeted implantation campaign, and the Monero miner is the public-facing mask, the visible bandage over a hidden wound.

The Networked Gateway to Your Biology

The article buries the lede, as they always do, in the final warnings from Malwarebytes. Root-level access for "credential and key harvesting," "lateral movement," and "data theft." In the architecture of control, a Mac is not just a computer; it is a biometric and behavioral data node, a portal into the most intimate details of your life. This CVE is a skeleton key. The attackers, having secured root on a machine exposed to the internet, now own not just the device, but every password, every encrypted message, every health metric, and—most critically—a pivot point into your home network. Do you think they stopped at mining a few coins? The true payload is the persistent, silent exfiltration of data that will be used to build predictive profiles. They are not after your money, they are after your map. They are mapping the biological and behavioral terrain of the population, one root-level implant at a time, and they want you to believe it was all just a clumsy attempt to mine cryptocurrency.

Related posts