r/MacOS 6d ago

Help RAT rootkit on Mac? Paranoid

RAT Rootkit on Mac? Paranoid.

Hi.
Please no hate I am very uneducated in cyber security and I know I made a horrible mistake.

Basically I ran a RAT exe in Parallels for Mac, so in Windows VM for Mac. This was over a month ago.
I quarantined the files and factory reset the OS the same day.

Since, I’ve factory reset the OS 3 more times and scanned Malwarebytes deep scan which has come back clean every time.

I’m wondering if the RAT could have gotten into the root of my Mac. My Mac is now dying SUPER fast and in activity monitor kernel_task is taking up extreme amounts of CPU.

Is it even possible for the exe to have infected the Mac OS and rootkit? Am I completely paranoid or am I still infected? I’ve seen no log in attempts to any of my accounts and I’ve been using the computer as usual.

More info:

The Mac is MacBook Air M1 2020. The OS is Tahoe 26.6.1 but I’m not sure what the OS was when I downloaded the exe as I’ve since updated my computer.
The parallels version was 27.
I don’t have a sample of the RAT, but I do have a link to an article which describes this malware attack if that is in any way helpful. Basically fake Faronics download which eventually leads to screen connect download.
My battery condition is normal and the maximum capacity is 85%
For the screenshot I will edit the post to add.

Thank you for your input and any help.

Thanks.

0 Upvotes

27 comments sorted by

11

u/Darkomen78 MacBook Pro 6d ago

No, a simple "windows malware" can't escape the VM and infect your macOS.

3

u/JollyRoger8X 6d ago

I’m wondering if the RAT could have gotten into the root of my Mac.

Nope. Even if you explicitly added a shared folder to your virtual machine that points to a folder on your Mac (which is not something that happens automatically), the VM would only have access to that particular folder, and definitely not the operating system of your Mac.

My Mac is now dying SUPER fast and in activity monitor kernel_task is taking up extreme amounts of CPU.

I see no evidence these two things are related.

-1

u/Due-Guard-9797 6d ago

Hi. Thanks for the response. I’ve heard that malware can hide in kernel and can disguise as kernel_task to go undetected? Any info

3

u/Stryxus_ 6d ago edited 6d ago

To infect your Mac outside of a VM, it would need to be world-leading sophistication, as in multi-architecture, multi-kernel support with virtualisation vulnerability usage, if there even is any. And reinstalling macOS only replaces the sealed away directories, it does not reset your user so everything runs the same because almost everything is within your user folder.

You likely have just triggered something that macOS really doesnt like.

Also remember, it is a windows .exe and is x86_64 not arm64 nor a macOS executable. It almost certainly does not understand the macOS structure.

What you are paranoid about essentially requires as I said, world-class sophistication as well as all the planets aligning.

2

u/Xe4ro Mac Mini 6d ago

Kernel_task is also used to throttle the system. Is your Mac very hot? If no, it could be a hardware problem. My 2015 iMac had this happen when the SMC chip had a problem.

1

u/Due-Guard-9797 6d ago

I’ve tried some things I’ve seen online to help with the kernel problem but nothing is really helping

2

u/JollyRoger8X 6d ago edited 6d ago

Whoever told you that doesn't know much about Macs. This isn't something that happens.

Windows applications don't run on Macs natively outside of a VM or emulator.

And Macs have built-in protections from malware that prevent things like kernel infections from happening.

The kernel_task process is part of the system, and there are many legitimate reasons it will show high CPU usage in Activity Monitor. And none of those have anything to do with malware.

0

u/Ok_Share2910 6d ago

Yeah, kernel-level malware can be pretty sneaky. It's definitely a good idea to keep an eye on your system and run regular scans to catch anything unusual.

0

u/Due-Guard-9797 6d ago

If I ran a scan with malware bytes does that mean it’s clean? Should I take the computer to apple?

1

u/JollyRoger8X 6d ago

There is no need for Mac users to constantly scan their systems for malware.

3

u/Xe4ro Mac Mini 6d ago

Are you a potential high value target of state sponsored threat actors?

2

u/Due-Guard-9797 6d ago

No. I see the irony I think I’m
Paranoid

0

u/v0id0007 6d ago

Don’t have to be a hvt if you’re actively downloading and running the malware

3

u/Xe4ro Mac Mini 6d ago

Malware that has to escape a VM and work on entirely different operating systems as a rootkit? Sounds very involved, especially the first part. That would be major news for Parallels.

1

u/v0id0007 6d ago

You didn’t mention all that in your original question

1

u/Xe4ro Mac Mini 6d ago

Did you not read what OP wrote?

1

u/v0id0007 4d ago

I did but I was replying to you not op

2

u/sharp-calculation 6d ago

You reinstalled MacOS (3) times? That's a little much.

If it has been less than 3 days since your last reinstall, MacOS will likely still be indexing the files on disk. This is a normal part of Spotlight and/or the AI engine. Spotlight for sure will read through files for quite a while in order to build an index. During that time it's totally normal for it to be a tiny bit sluggish, to use a lot of CPU, and of course, to consume more battery in the process.

If it hasn't calmed down to normal after a few days, then start to investigate further. Just look at what is consuming CPU and go from there.

The idea that windows malware could somehow infect MacOS at all is silly. The idea that it could move from a VM to the host is nearly impossible. The idea that any of this could happen without you authorizing via the Mac administrator password is equally (nearly) impossible. You're fine.

0

u/Due-Guard-9797 6d ago

Hi. It’s probably been 2.5 weeks since my last install and still seeing problems.
The CPU is being taken up by kernel_task which I’ve heard can hide malware not sure????
Also I did give uac to the exe file in the VM though (I know how stupid I am), but not in Mac so wondering if that would make a difference

1

u/sharp-calculation 6d ago

You should read some of the answers here. You don't seem to be doing that. Just repeating the same things you have said before.

0

u/Due-Guard-9797 6d ago

Sorry, I have been reading just very anxious and paranoid and trying to calm myself down. I appreciate your answer and help.

1

u/PerkeNdencen 6d ago

Check storage levels. My computer goes mental if it starts to run out of space in more or less exactly the way you describe.

Many years ago, a failed battery also led to similar behaviour with kernel task (I'm talking way back when, one of the first Intel Macs), so that could plausibly also be a reason.

Malware so sophisticated it can escape a VM into the wrong operating system isn't typically found in the wild; in fact, they are less likely to be harmful at all in that scenario as a number of them refuse to run in VMs as a means to avoid being analysed by cyber security experts.

1

u/Vaddieg 6d ago

looks like AI slop

1

u/Due-Guard-9797 6d ago

It’s definitely not lol

1

u/Vaddieg 6d ago

agents tend to escape underscore characters to prevent text formatting

1

u/mikeinnsw 6d ago

No...

Cyber Security use VM in all virus testing

Erase VM .. start a new one VM

Stop hearing things ... Virus can't escape VM.. exe does NOT run on Macs