Hackers Are Abusing a macOS Screen Sharing Flaw to Secretly Mine Monero
The Netherlands' NCSC warned of active exploitation of a macOS Screen Sharing vulnerability across systems with port 5900 exposed to the internet, where attackers gained root access and installed Monero mining programs.
Intelligence analysis by Llama

Hackers are exploiting a macOS Screen Sharing vulnerability to secretly mine Monero on victims' hardware. The flaw stems from faulty state management during authentication, letting network attackers log in without valid credentials.
Hackers are using a flaw in macOS to secretly install software that mines a type of cryptocurrency called Monero. This allows them to use people's computers to make money without their knowledge or permission.
Analysis
Vulnerability Exploitation
The Netherlands' National Cyber Security Center (NCSC) has warned of active exploitation of a macOS Screen Sharing vulnerability across systems with port 5900 exposed to the internet. This vulnerability allows attackers to gain root access and install Monero mining programs on victims' hardware. The flaw stems from faulty state management during authentication, letting network attackers log in without valid credentials.
Cryptojacking Campaign
The cryptojacking campaign, which quietly mines privacy coin Monero on victims' hardware, joins a wave of similar schemes. Attackers have been exploiting a vulnerability in Apple's macOS Screen Sharing feature to seize control of Macs and quietly install cryptocurrency miners. The NCSC has received reports of this exploitation and has issued an updated advisory to warn users of the potential threat.
Implications
The implications of this vulnerability are significant, as it allows hackers to gain root access and install malicious software on victims' hardware. This can lead to a range of consequences, including the theft of sensitive information and the compromise of system security. The fact that this vulnerability is being exploited to mine Monero is particularly concerning, as it highlights the potential for hackers to use this vulnerability for financial gain.
Key points
- Hackers are exploiting a macOS Screen Sharing vulnerability to secretly mine Monero on victims' hardware.
- The flaw stems from faulty state management during authentication, letting network attackers log in without valid credentials.
- The NCSC has warned of active exploitation of this vulnerability across systems with port 5900 exposed to the internet.
- Attackers have been exploiting a vulnerability in Apple's macOS Screen Sharing feature to seize control of Macs and quietly install cryptocurrency miners.
If this vulnerability is patched quickly, the number of Macs affected by this exploitation could be significantly reduced, limiting the potential for hackers to use this vulnerability for financial gain.
The fact that this vulnerability is being exploited to mine Monero is particularly concerning, as it highlights the potential for hackers to use this vulnerability for financial gain. If this exploitation continues unchecked, it could lead to a range of consequences, including the theft of sensitive information and the compromise of system security.



