PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

Silver Sparrow Malware Discovered on 30K Infected Macs

Infections have been confirmed in 153 countries and this new malware can also target M1 Macs.

 & Matthew Humphries Former Senior Editor

Our team tests, rates, and reviews more than 1,500 products each year to help you make better buying decisions and get more from technology.

Our Expert
LOOK INSIDE PC LABS HOW WE TEST
65 EXPERTS
43 YEARS
41,500+ REVIEWS

If a reminder were needed that no platform is safe from infection, a brand new strain of malware has been found hiding on 30,000 Macs waiting to be told what to do.

As Ars Technica reports, the new macOS malware was discovered by security vendor Red Canary, with the company naming this unusual strain "Silver Sparrow." Why is it unusual? As Red Canary's Tony Lambert explains, Silver Sparrow "did not exhibit the behaviors that we’ve come to expect from the usual adware that so often targets macOS systems. The novelty of this downloader arises primarily from the way it uses JavaScript for execution—something we hadn’t previously encountered in other macOS malware."

Silver Sparrow is also unusual because it's only the second known piece of malware capable of targeting Apple's new M1 ARM architecture Macs, and because it hasn't done anything yet. Macs located in 153 different countries are known to be infected, although the highest volumes are found in the United States, United Kingdom, Canada, France, and Germany.

Silver Sparrow is being taken very seriously because of how successful it has already been at quietly infecting over 30,000 Macs around the world, but also because the malware is using Amazon Web Services and Akamai for its command infrastructure. That means it could prove very difficult to take down.

For now, every Mac infected with Silver Sparrow communicates with a control server every hour to see if there's new commands to carry out. So far, none seem to have been issued. The researchers also discovered the malware includes the capability to remove itself from a system, meaning it could be used to execute a command then promptly disappear.

Lambert points to many intelligence gaps that need to be filled with regards to Silver Sparrow. "In addition, the ultimate goal of this malware is a mystery. We have no way of knowing with certainty what payload would be distributed by the malware, if a payload has already been delivered and removed, or if the adversary has a future timeline for distribution. Based on data shared with us by Malwarebytes, the nearly 30,000 affected hosts have not downloaded what would be the next or final payload."

Anyone wanting to check if their Mac is infected with Silver Sparrow can read through the "Indicators of Compromise" section of the Red Canary blog post for some pointers on what to look for.

About Our Expert

Matthew Humphries

Matthew Humphries

Former Senior Editor

My Experience

I started working at PCMag in November 2016, covering all areas of technology and video game news. Before that I spent nearly 15 years working at Geek.com as a writer and editor. I also spent the first six years after leaving university as a professional game designer working with Disney, Games Workshop, 20th Century Fox, and Vivendi.

I hold two degrees: a Bachelor's degree in Computer Science and a Master's degree in Games Development. My first book, Make Your Own Pixel Art, is available from all good book shops.

My Areas of Expertise

  • PC components and system building
  • Raspberry Pi
  • Software development
  • Storage technology
  • Video games and gaming hardware

Read full bio