Banshee Stealer is a macOS-focused information stealer that emerged in August 2024 and was marketed as a malware-as-a-service offering associated with Russian-speaking cybercrime actors. It supports both x86_64 and ARM64 macOS systems. The malware collects host software and hardware details, browser history, cookies, login data, Safari cookies, Keychain material, Apple Notes data, selected documents, cryptocurrency-wallet data, and data associated with numerous browser extensions. It targets major Chromium-based browsers, Firefox, and Safari, as well as several desktop cryptocurrency wallets.
Banshee uses AppleScript-generated dialogs impersonating system prompts to obtain the macOS user password and validates supplied credentials locally. It performs anti-analysis checks for debugging, virtualized environments, and Russian-language configurations, and may mute system audio during execution. Collected data is staged in a temporary directory, compressed, XOR-encrypted, Base64-encoded, and sent to command-and-control infrastructure through HTTP POST requests. Its source code leaked in November 2024, after which the operators reportedly ceased operations; the leak also enabled derivative macOS infostealer variants.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
BANSHEE Stealer supports basic evasion techniques, relies on the sysctl API to detect debugging and checks for virtualization by running a command to see if “Virtual” appears in the hardware model identifier.
It copies the keychain of the system /Library/Keychains/login.keychain-db to <temporary_path>/Passwords.
The malware creates an Osascript password prompt... When the user enters the password, it will be validated using the dscl command.
Regarding Safari, only the cookies are collected by the AppleScript script for the current version.
Wallets.cpp [is] responsible for collecting data from cryptocurrency wallets... Exodus, Electrum, Coinomi, Guarda, Wasabi Wallet, Atomic, Ledger.
These credentials can be leveraged to decrypt the keychain data stored on the system, granting access to all saved passwords.
It gets the machine's public IP by requesting it from freeipapi.com through the built-in macOS cURL command.
When the user enters the password, it will be validated using the dscl command by running dscl Local/Default -authonly <username> <password>.
The function System::collectSystemInfo collects system information... It executes the command system_profiler SPSoftware DataType SPHardwareDataType.
It then collects various files from the system... Files with the following extensions .txt, .docx, .rtf, .doc, .wallet, .keys, or .key from the Desktop and Documents folders.
BANSHEE Stealer supports basic evasion techniques, relies on the sysctl API to detect debugging and checks for virtualization by running a command to see if “Virtual” appears in the hardware model identifier.
It runs the command system_profiler SPHardwareDataType | grep 'Model Identifier' to determine whether the string Virtual appears in the hardware model identifier.
It then collects various files... .txt, .docx, .rtf, .doc, .wallet, .keys, or .key from the Desktop and Documents folders.
The malware creates an Osascript password prompt... When the user enters the password, it will be validated using the dscl command.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example of existing macOS malware in background context only.
macOS information stealer with a newer variant adding advanced string encryption inspired by Apple XProtect to evade detection.
macOS-focused infostealer whose leaked source code enabled defenders to improve detection and other developers to create derivative stealers.
A macOS-focused MaaS infostealer that targets x86_64 and ARM64 systems. It steals browser data, keychain passwords, cookies, logins, browsing history, cryptocurrency wallet data, and browser extension data; uses basic anti-debugging and anti-virtualization checks; avoids Russian-language systems; compresses stolen data into a ZIP, XOR-encrypts and base64-encodes it, then exfiltrates it via POST using cURL.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.