The first M1 MacBook malware has arrived – here's what you need to know

Apple M1
(Image credit: Apple)

The first malware native to M1-powered MacBooks has been discovered in the wild, just months after the arrival of the first Apple Silicon devices.

News of the first M1 malware comes via ex-NSA researcher and longtime Mac security researcher Patrick Wardle, who has uncovered the existence of GoSearch22.app, an M1-native version of the longstanding Pirrit virus.

"Today we confirmed that malicious adversaries are indeed crafting multi-architecture applications, so that their code will natively run on M1 systems," says Wardle in a blog post. "The malicious GoSearch22 application may be the first example of such natively M1 compatible code."


Wardle notes that the adware – a type of malware that generates revenue by spamming users with pop-ups and adverts – was signed with an Apple developer ID, a paid account that allows Apple to keep track of all Mac and iOS developers, on November 23. 

Having a developer ID also means Having a user downloading the malware wouldn’t trigger Gatekeeper on macOS, which notifies users when an application they’re about to download may not be safe. 

What’s more, Wardle says that a number of current antivirus systems that could spot the Intel versions of the Pirrit virus failed to identify the M1 version.

“Certain defensive tools like antivirus engines struggle to process this 'new' binary file format,” Wardle says. “They can easily detect the Intel-x86 version, but failed to detect the ARM-M1 version, even though the code is logically identical.”

Apple has yet to respond to Wardle's findings, but the the company has revoked the GoSearch22 certificate.

The first M1 malware has likely arrived sooner than many expected, as hackers typically look to exploit lucrative targets. Apple only introduced its first M1 Macs in November, and the ARM-based chip is currently limited to the latest models of the MacBook Air, MacBook Pro and Mac mini. 

Thankfully, for the few that already own an Apple Silicon Mac, the GoSearch22 threat doesn’t seem too dangerous. However, it's undoubtedly a sign that more M1-native malware is on the horizon.

Via: Wired

TOPICS
Carly Page

Carly Page is a Freelance journalist, copywriter and editor specialising in Consumer/B2B technology. She has written for a range of titles including Computer Shopper, Expert Reviews, IT Pro, the Metro, PC Pro, TechRadar and Tes. 

Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
A fresh Samsung Galaxy S25 Edge leak hints at a 2K display and a titanium frame