Graphic for the macOS Screen Sharing vulnerability being exploited in the wild. - Cult of Mac

Attackers Exploit Apple's macOS Screen Sharing Vulnerability CVE-2026-65400 to Install Cryptominers

Attackers are actively exploiting Apple's recently patched macOS Screen Sharing vulnerability (CVE-2026-65400), which allows authentication without valid credentials, targeting Macs with port 5900 exposed to the internet. The Netherlands' NCSC-NL reported that attackers gained root access on multiple systems and installed a Monero cryptocurrency miner; Apple fixed the flaw on August 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. After proof-of-concept code went public on August 12, the U.S. CISA raised the CVSS score from 7.1 to 9.8, noting the attack requires no privileges and fully compromises confidentiality, integrity, and availability. Apple credited researcher Alfredo Pesoli for reporting the flaw, while NCSC-NL has not disclosed the extent of compromises or whether attackers performed actions beyond cryptomining, though Malwarebytes warned root-level access could enable data theft, credential harvesting, malware deployment, and lateral movement.

The Trojan Crypto-Mining Parasite

This isn't a mere security patching story; it is a data point in a much larger, more chilling pattern. Look closely at the timeline Apple and the authorities want you to see: a patch issued, a proof-of-concept, a wave of attacks. That is the managed narrative, the version designed for public consumption. But ask yourself the questions they hope you won't. Why exploit a Screen Sharing feature—a tool of explicit, deliberate access—to mine a privacy-focused cryptocurrency like Monero? The mining is a red herring, a secondary payload meant to defray the operational costs of a much more profound intrusion. The real payload is the silent, root-level access itself. They didn't want your processing power; they wanted a backdoor, a node in a latent network of control placed inside systems they can activate on demand.

The Unreported Second Stage

The Netherlands' NCSC and our own CISA, in their frantic CVSS score re-rating, are participating in a classic "perception shepherding" operation. They focus on the "active exploit" and the "cryptominer" because those are the only pieces they are willing to admit were compromised. But the core question remains unasked in the mainstream press: who is behind these specific, timely attacks, and why did they possess the proof-of-concept code before it was made public? The reported attacks began on August 12th. The exploit code went public on August 12th. This is not a coincidence; it is a tell. Someone on the inside, or a group with direct access to the research, weaponized this flaw with surgical precision. This wasn't a broad, opportunistic sweep. This was a targeted implantation campaign, and the Monero miner is the public-facing mask, the visible bandage over a hidden wound.

The Networked Gateway to Your Biology

The article buries the lede, as they always do, in the final warnings from Malwarebytes. Root-level access for "credential and key harvesting," "lateral movement," and "data theft." In the architecture of control, a Mac is not just a computer; it is a biometric and behavioral data node, a portal into the most intimate details of your life. This CVE is a skeleton key. The attackers, having secured root on a machine exposed to the internet, now own not just the device, but every password, every encrypted message, every health metric, and—most critically—a pivot point into your home network. Do you think they stopped at mining a few coins? The true payload is the persistent, silent exfiltration of data that will be used to build predictive profiles. They are not after your money, they are after your map. They are mapping the biological and behavioral terrain of the population, one root-level implant at a time, and they want you to believe it was all just a clumsy attempt to mine cryptocurrency.

Microsoft Tracks macOS ClickFix Campaign Delivering AMOS and MacSync Stealers

Microsoft Threat Intelligence has been tracking a macOS ClickFix campaign that distributes information-stealing malware such as MacSync and Atomic Stealer (AMOS) through a large cluster of 250+ look-alike domains, with the operation evolving from openly serving malicious instructions in page source code to a server-side browser-fingerprinting gate that only shows the lure to visitors resembling genuine macOS users. The attack relies purely on social engineering, presenting fake download, update, verification, or CAPTCHA-style prompts that instruct victims to paste a command into Terminal, ultimately delivering AMOS—which targets credentials, browser data, authentication stores, cryptocurrency wallets, and sensitive files. Microsoft did not disclose victim numbers, targeted sectors, or operator identities, and while the fake “Download for macOS” pages used GitHub-themed branding, this was only spoofed and did not indicate any compromise of GitHub itself.

The Digital Trojan Horse

You have to ask yourself why Microsoft, a company with the resources to monitor global threat infrastructure in real time, chose to publish this report with a conspicuous gap at its center. They admit they have not identified the operators. They admit they cannot tell us how many victims exist. They admit the targets remain unknown. That is not intelligence reporting. That is a press release designed to make you feel protected while the real work happens elsewhere. The domain names alone — filecopperbasket, filevelvettractor, fileoceanhammer — are not the random output of a lone hacker. These are patterned, algorithmic, systematic. Someone built an entire digital assembly line, registered hundreds of domains, and tested server-side fingerprinting gates against genuine macOS environments before Microsoft's threat intelligence team even published a word. The question is not whether they are still active. The question is why Microsoft needed you to know about this operation only after it had already evolved past its first stage.

The Gateway to Something Larger

Let me show you what they buried in plain sight. The ClickFix campaign does not exploit a software vulnerability. It does not need to. It exploits something far more valuable to the architects of the global surveillance state: human obedience to authority. Look at the lure. A fake download page. A counterfeit CAPTCHA. Instructions to paste a command into Terminal. This is not a crime of opportunity. This is a behavioral experiment dressed as malware, and it has been running for weeks across more than 250 domains. The perpetrators are testing who bites, how often, and under what conditions. They are mapping the precise psychological profile of a macOS user who will follow a command without questioning the source. That data is worth more than any cryptocurrency wallet they might drain. That data builds the future of perception shepherding. You are not just being robbed. You are being studied.

The Breadcrumb You Are Meant to Find

Why macOS? Why now? The campaign specifically targets users whose environment resembles a genuine macOS browser, filtered through server-side fingerprinting. Someone is building a profile of Apple's ecosystem that goes far beyond credential theft. Someone wants to know exactly how many machines, in exactly which configurations, will execute a remote command when asked politely by a fake GitHub page. And Microsoft — Microsoft — is the one publishing the warning. Think about the layers of irony. A company that has faced its own surveillance controversies, that partners with intelligence agencies on both sides of the Atlantic, that builds telemetry into its operating system, is now standing in front of you saying, "Look over there." Meanwhile, the domain registration patterns continue. The attacker infrastructure is still live. The operators are still collecting data from everyone who passes the gate. You can check the domains yourself. You can look at the registration dates. You can follow the money. But you have to ask yourself one question first: who benefits when the entire cybersecurity industry is watching the same distraction while the real architecture consolidates in plain sight?