Banshee Stealer is a macOS infostealer attributed to Russian-speaking threat actors and marketed as a malware-as-a-service offering. It targets both Intel and Apple Silicon macOS systems and is designed to harvest browser data, stored credentials, cookies, keychain material, cryptocurrency wallet data, and information from a large set of browser extensions. Reported targets include major Chromium-based browsers, Firefox, and Safari, as well as desktop cryptocurrency wallets.
The malware uses AppleScript extensively to interact with the victim, including muting system audio, presenting password prompts, and accessing sensitive local data such as Safari cookies and keychain contents. Collected information is staged locally, compressed into an archive, obfuscated with XOR and Base64 encoding, and then exfiltrated to attacker-controlled infrastructure over HTTP using command-line tooling.
Banshee Stealer incorporates anti-analysis and defense-evasion features, including debugger and virtualization checks via macOS system APIs. It also performs locale checks and avoids infecting systems configured for the Russian language, a behavior commonly associated with malware developed in Russian-speaking cybercriminal ecosystems. In late 2024, the malware’s source code leaked publicly, after which the original operation reportedly shut down. The leak contributed to improved defensive detection while also enabling derivative macOS stealers and variants to emerge from the reused codebase.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
It uses AppleScripts for tasks like muting system sound, phishing for user passwords, and copying keychain data.
BANSHEE Stealer targets nine browsers for browser data collection—Chrome, Firefox, Brave, Edge, Vivaldi, Yandex, Opera, OperaGX, and Safari - extracting history, cookies, and login credentials.
The malware employs basic anti-analysis techniques, such as debugging and virtualization detection using the sysctl API and system profiling commands.
BANSHEE Stealer is designed to collect a wide range of data from infected systems, including browser history, cookies, logins, cryptocurrency wallets, and around 100 browser extensions.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example of existing macOS malware in background context only.
macOS information stealer with a newer variant adding advanced string encryption inspired by Apple XProtect to evade detection.
macOS-focused infostealer whose leaked source code enabled defenders to improve detection and other developers to create derivative stealers.
macOS infostealer that collects browser history, cookies, login credentials, cryptocurrency wallet data, and data from around 100 browser extensions. It uses anti-analysis checks, avoids Russian-language systems, leverages AppleScript for password phishing and keychain copying, then compresses, XOR-encrypts, Base64-encodes, and exfiltrates stolen data to a remote server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.