Summary
- The Dutch National Cyber Security Center (NCSC) has alerted users about the exploitation of a macOS Screen Sharing vulnerability, particularly on systems with port 5900 exposed to the internet, leading to unauthorized root access and the installation of Monero mining software.
- This vulnerability arises from improper state management during the authentication phase, allowing attackers to log in without valid credentials.
- This cryptojacking operation, which stealthily uses victims' hardware to mine Monero, is part of a larger trend of similar attacks.
According to a warning issued this week by the NCSC, hackers are taking advantage of a flaw in Apple’s macOS Screen Sharing functionality to gain control over Mac computers and discreetly install cryptocurrency mining tools.
The NCSC's updated advisory indicates that multiple systems with port 5900—designated for Screen Sharing—exposed to the internet have been targeted by these attacks.
Myriad: When will OpenAI release GPT-6? Click to make your prediction.In these incidents, attackers have successfully gained root access, which is the highest level of control over a device, and have deployed a Monero mining application to exploit the victim's hardware resources. Monero is classified as a privacy coin, making it difficult to trace compared to more transparent cryptocurrencies like Bitcoin or Ethereum. The NCSC has also noted that public proof-of-concept code for this vulnerability is circulating, which could make it easier for potential attackers to exploit the flaw.
This issue, identified as CVE-2026-65400 and rated 7.1 out of 10 on the severity scale, is an authentication error caused by inadequate state management during the login process. This allows attackers to bypass authentication checks that should normally reject unauthorized login attempts.
Apple has responded by releasing patches in macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1 to enhance validation checks. Users who have not yet updated, especially those with Screen Sharing accessible from the internet, remain at risk.
Monero has historically been favored by cybercriminals engaging in cryptojacking, where compromised machines mine cryptocurrency for the attackers while the victims bear the costs of electricity and reduced performance. The privacy features of Monero make tracking the mined funds significantly more challenging than with Bitcoin.
This incident is part of a continuous series of schemes that exploit users' devices for unauthorized crypto mining.
Earlier this month, Bitdefender reported finding pirated versions of "The Odyssey" embedded with the Lumma Stealer malware designed to drain cryptocurrency wallets. Decrypt has also covered malware disseminated through fake CAPTCHA pages routed via BNB Chain, the SparkKitty operation that concealed wallet-stealing malware in mobile applications, and malicious "anime girl" wallpapers targeting Steam users, as well as crypto-theft code embedded in a compromised Python library.
The NCSC advises users to promptly apply Apple’s updates and to refrain from leaving Screen Sharing accessible from the internet, which is how attackers gained entry initially.
