• Send Us A Tip
  • Calling all Tech Writers
  • Advertise
Monday, June 22, 2026
  • Login
TechStory
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
TechStory
No Result
View All Result
Home Gadgets

Popular windows malware XLoader has migrated to MacOS, for dirt cheap prices

by Aashish Sehrawat
July 26, 2021
in Gadgets, News, Tech
Reading Time: 2 mins read
0
Credit: Malwarebytes
TwitterWhatsappLinkedin

Credit: Malwarebytes

You might also like

Porsche Taycan Wagons Bow Out in the US as Sport Turismo and Cross Turismo Face the Axe

How Long Do Honda Civics Last? Why the Compact Sedan Still Has a Long-Life Reputation

SpaceX-Linked ETFs Attract $8.2 Billion as Analysts Warn Mega IPOs Could Reshape Global Indices

XLoader is an evolutionary and more powerful version of the malware Formbook. It has now migrated to MacOS as well, and is more dangerous than before. It lets an attacker log keystrokes, take screenshots, and access other private information.

It’s already quite popular on dark web stores, say reports by Check Point Research (CPR), proving that government’s, as well as our idea of cybercrime, is really narrow, and we should be more aware of it.

What’s even more worrying is that this malware is sold for really cheap prices, as low as $50 per month. Yes, per month, this malware has also adapted to the new subscription model of using softwares. It’s just like subscribing to Adobe Creative Cloud, we pay the developer as long as we wish to use their service.

Formbook primarily targeted Windows users but disappeared from being on sale in 2018. Formbook rebranded to XLoader in 2020.
This exists a significant potential threat to all Mac users. In 2018, Apple estimated that over 100million macOS devices in use. Check Point Research tracked Xloader activity between December 1, 2020 and June 1, 2021, and saw XLoader requests from as many as 69 countries. Over half (53%) of the victims reside in the United States.

XLoader is stealthy, meaning it is hard to tell when a Mac is infected with it, but the company does provide one method of checking:-

1. Go to /Users/[username]/Library/LaunchAgents directory
2. Check for suspicious filenames in this directory (example below is a random name)
/Users/user/Library/LaunchAgents/com.wznlVRt83Jsd.HPyT0b4Hwxh.plist

Only we can protect our devices from XLoader being installed, as it is mainly spread through phishing methods like spoofed emails. Those emails usually contain malware-infected MS Office documents which if downloaded, infects our device with malware. We shall be careful around downloading things on our devices and send those spoofy emails directly to the junk folder.

“Historically, macOS malware hasn’t been that common. They usually fall into the category of ‘spyware’, not causing too much damage.
I think there is a common incorrect belief with macOS users that Apple platforms are more secure than other more widely used platforms,” said Yaniv Balmas, head of cyber research for Check Point. “While there might be a gap between Windows and macOS malware, the gap is slowly closing over time. The truth is that macOS malware is becoming bigger and more dangerous. Our recent findings are a perfect example and confirm this growing trend.” said Yaniv Balmas, head of cyber research at Check Point Software.

Tags: #macosAppleCybercrimedarkwebMacBookMalwarePhishingsecurityvisruswindows
Tweet54SendShare15
Previous Post

Sony Renews Playstation Home Trademark Again

Next Post

Upcoming Cyberpunk game “Vigilance 2099” Is Aiming For A Console Release

Aashish Sehrawat

Recommended For You

Porsche Taycan Wagons Bow Out in the US as Sport Turismo and Cross Turismo Face the Axe

by Samir Gautam
June 22, 2026
0
Porsche Taycan Wagons Discontinued in the US After 2026

Porsche is preparing to shrink the Taycan family in the United States, confirming that the Sport Turismo and Cross Turismo variants will be discontinued after the 2026 model...

Read more

How Long Do Honda Civics Last? Why the Compact Sedan Still Has a Long-Life Reputation

by Samir Gautam
June 21, 2026
0
Honda Civic lifespan guide

The Honda Civic has spent decades building a reputation as one of the safest bets in the compact-car market. It is affordable to run, easy to live with...

Read more

SpaceX-Linked ETFs Attract $8.2 Billion as Analysts Warn Mega IPOs Could Reshape Global Indices

by Rounak Majumdar
June 21, 2026
0
SpaceX-Linked ETFs Attract $8.2 Billion as Analysts Warn Mega IPOs Could Reshape Global Indices

Exchange-traded funds offering exposure to SpaceX have attracted approximately $8.2 billion in investor inflows, highlighting the growing appetite for private-market companies that are not directly available to public...

Read more
Next Post
Vigilance 2099

Upcoming Cyberpunk game "Vigilance 2099" Is Aiming For A Console Release

Please login to join discussion

Techstory

Tech and Business News from around the world. Follow along for latest in the world of Tech, AI, Crypto, EVs, Business Personalities and more.
reach us at info@techstory.in

Advertise With Us

Reach out at - info@techstory.in

Aviator Game India 2026

BROWSE BY TAG

#Crypto #howto 2024 acquisition AI amazon Apple Artificial Intelligence bitcoin Business China cryptocurrency e-commerce electric vehicles Elon Musk Ethereum facebook funding Gaming Google India Instagram Investment ios iPhone IPO Market Markets Meta Microsoft News OpenAI samsung Social Media SpaceX startup startups tech technology Tesla TikTok trend trending twitter US

© 2025 Techstory.in

No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to

© 2025 Techstory.in

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?