Threat Research Knowledge Base Threats Banshee
Banshee
Description
Banshee is a sophisticated macOS infostealer that poses a significant threat to Apple users. It is designed to exfiltrate a wide range of sensitive information, including system data, login credentials, and, cryptocurrency wallets.
Variant Names
N/A
Alternative Names
N/A
Country of origin
- Russia
Symptoms
You might observe the following artifacts associated with this threat:
- Unexpected prompts requesting system passwords.
- Unusual activity in cryptocurrency wallets and browser extensions.
- Presence of unfamiliar files or scripts in the
/tmp
directory.
Technical Breakdown
Banshee is malware capable of collecting extensive data from the system, browsers, and cryptocurrency wallets. Despite its potentially dangerous capabilities, Banshee's lack of sophisticated obfuscation and the presence of debug information make it easier for analysts to reverse engineer. While Banshee Stealer is not overly complex in its design, its focus on macOS systems and the breadth of data it collects make it a significant threat that demands attention from the cybersecurity community.
Some of Banshee's capabilities include:
- Collecting system information, including software and hardware details.
- Stealing user passwords by prompting for credentials under false pretenses.
- Dumping keychain passwords, granting access to saved credentials.
- Exfiltrating browser data such as history, cookies, and login information from multiple browsers.
- Targeting cryptocurrency wallets and related browser extensions.
Next Steps
Kandji Endpoint Detection & Response (EDR) automatically removes detected threats when file monitoring is set to Protect.
While the malicious file is removed, it can leave behind artifacts that need to be cleaned manually.
In the future, avoid downloading and installing software from torrent sources or untrusted websites. Ensure that all applications are obtained from official and reputable sources to maintain system integrity and security.
Learn more about it

Banshee Rust Rewrite?
Banshee is a sophisticated macOS infostealer that poses a significant threat to Apple users. It is designed to exfiltrate a wide range of sensitive information, including system data, login credentials, and cryptocurrency wallets. The malware's capabilities include collecting system information, stealing user passwords, dumping keychain passwords, exfiltrating browser data, and targeting cryptocurrency wallets and related browser extensions.
Read moreRelated
Atomic Stealer (AMOS) is a sophisticated piece of malware that targets Apple users by masquerading as legitimate applications. Once installed, AMOS can exfiltrate extensive data, including keychain passwords, user documents, system information, browser data, credit card information, and cryptocurrency wallets. There is a strong association between Atomic Stealer and Russian-speaking cybercriminal communities.
Cuckoo is an info stealer that typically masquerades as macOS applications such as Homebrew and Google Chrome. Discovered by Kandji in 2024, it has been known to steal passwords, as well as recording audio and video from an infected system.
Poseidon (RodrigoStealer) is an information stealer targeting macOS users, masquerading as legitimate applications such as the Arc browser. It is designed to exfiltrate sensitive data, including system information, browser credentials, cryptocurrency wallets, and documents. It has been associated with Russian-speaking cybercriminal communities and is actively distributed through phishing campaigns and compromised websites.
Manage and secure your Apple devices at scale.
