Internet-Exposed Macs Targeted via Screen Sharing Vulnerability That Installs Monero Miner

Internet-Exposed Macs Targeted via Screen Sharing Vulnerability That Installs Monero Miner

A flaw in Apple's macOS Screen Sharing feature is being actively exploited on Macs reachable from the internet, allowing attackers to install a Monero miner that drains computing power.

Security researchers are warning about a vulnerability in the Screen Sharing component of Apple's macOS operating system that is being actively exploited on Mac computers exposed directly to the internet. Screen Sharing is a built-in feature that allows someone to view or control the Mac's screen from another device. Attackers who find an internet-exposed Mac with this feature enabled can break in and silently install a Monero miner, a program that uses the computer's processor and graphics chip to generate the privacy-focused cryptocurrency Monero for the attacker's benefit.

Monero is a digital currency designed to make transactions difficult to trace, which is why cybercriminals often choose it over more transparent cryptocurrencies like Bitcoin. A mining program running in the background can consume nearly all of a computer's processing power, causing the machine to become extremely slow, overheat, and use more electricity. For a business or a website owner who relies on a Mac for daily work, this kind of infection can lead to lost productivity and potentially higher energy bills, and in some cases the added heat can shorten the lifespan of hardware components.

The key factor that makes this attack possible is direct exposure to the internet. In normal home or office networks, a router or firewall blocks unsolicited incoming connections from the outside. But some users, especially those who do remote technical support or connect to their Mac while traveling, may enable Screen Sharing and open the necessary network ports without restricting access. If the Mac is assigned a public IP address or if port forwarding rules are set up, anyone on the internet can attempt to connect to the Screen Sharing service. Attackers use automated scanning tools to find such machines and then try to exploit the security flaw to gain control.

Once an attacker gains control of a Mac through Screen Sharing, they can do more than just install a miner. The compromised machine could be used as a jumping-off point to reach other devices on the same local network, including web servers or development systems that contain website files and sensitive data. For website owners and IT teams, a single infected Mac in the office can put an entire web infrastructure at risk if that Mac has saved passwords or secure shell keys for the hosting environment. This is why endpoint security, the protection of individual computers and devices, remains critical even for those who focus mainly on web hosting and online services.

Apple has not yet provided specific details about a patch in the report, but users can take immediate steps to reduce risk. The most important is to turn off Screen Sharing unless it is genuinely needed. If remote access is required, restrict it so that only specific trusted computers on the local network can connect, and never expose the service directly to the internet. Using a virtual private network (VPN) to connect to the home or office network is far safer than opening Screen Sharing to the public. Regularly updating macOS also ensures that any fixes Apple releases are applied as soon as possible. Watch for unexplained slowdowns or fans running at full speed, and check Activity Monitor to see if the CPU is constantly near 100 percent, which can indicate a hidden miner.

For businesses and website owners who manage Macs or mixed environments, AEU-I offers security-first IT and infrastructure consulting that can help assess exposure, harden remote access settings, and monitor for signs of unauthorized crypto mining activity. Staying protected starts with basic hygiene: disable remote features you do not use, keep all software up to date, and watch for unexplained slowdowns or fans running at full speed, which are common signs of a hidden miner.

How to Protect Yourself

  1. Turn off Screen Sharing in System Settings (or System Preferences) if you do not use it, and keep it off unless you need remote access.
  2. If you must use Screen Sharing, do not open your Mac to the internet; instead use a VPN to connect to your home or office network first.
  3. Check your router's port forwarding settings and remove any rules that forward Screen Sharing ports (usually 5900) to your Mac.
  4. Keep macOS updated by turning on automatic updates so you get security fixes as soon as Apple releases them.
  5. Watch for signs of a hidden miner: your Mac is unusually slow, fans are loud, battery drains quickly, or the CPU is near 100 percent in Activity Monitor.
  6. Run a malware scan with a trusted security tool for Mac if you suspect your computer has been infected.

Related AEU services

  • AEU-I IT and security consulting