macOS Screen Sharing: an authentication bypass actively exploited to mine Monero

Cybersecurity Aug 14, 2026Add to bookmarks

Cybersecurity

The Dutch NCSC warns: an active campaign is exploiting a macOS screen-sharing vulnerability to deploy a cryptocurrency miner. The exploit code is public—time to patch.

What

An authentication bypass vulnerability in macOS Screen Sharing functionality is being actively exploited to deploy a Monero (XMR) cryptocurrency miner. The alert comes from the Dutch NCSC (National Cyber Security Centre) - a public exploit code has recently emerged, accelerating ongoing attacks.

Who is affected

All macOS systems with screen sharing enabled and unpatched are potentially exposed. The attack surface notably includes developer workstations and macOS build machines - common targets in tech teams.

Analysis

Cryptocurrency miners are often perceived as “less dangerous” compared to ransomware, but they reveal something more concerning: an unauthorized, full, and reproducible remote code execution capability. An attacker capable of deploying a miner can, through the same vector, deploy any payload: RAT (Remote Access Trojan), infostealer, or ransomware.

The choice of Monero is deliberate: XMR is a privacy-focused cryptocurrency using ring signatures and stealth addresses, which significantly complicates fund tracing and attack attribution.

Why Monero?

Monero uses ring signatures and stealth addresses to hide the sender, recipient, and amount of each transaction - unlike Bitcoin, whose blockchain is public and fully traceable.

What to do now

  1. Check if Screen Sharing is enabled: System Settings → General → Sharing → disable “Screen Sharing” if not needed.
  2. Apply available macOS updates as soon as possible - patching is the only true protection.
  3. Audit active processes: a Monero miner consumes CPU massively. Identify unknown processes with high CPU usage via Activity Monitor or top -o cpu in Terminal.
  4. Outbound firewall: block connections to known mining pools (ports 3333, 5555, 7777 are frequently used by XMR miners).
Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

SSHSelf-hostedAI Ops
Get early access
Was this article helpful?

7 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

Get early access
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information