Mac malware removal

How to remove a virus or malware from a Mac

Macs do get malware, and the kind that matters today is not adware but info stealers such as Atomic (AMOS) that empty your Keychain, browser passwords and crypto wallets in minutes. This guide shows how they get in, where they hide on macOS Sonoma 14, Sequoia 15 and later, how to remove them and what to change afterwards.

How to remove malware from a Mac in five steps, next to a fake install page that asks you to paste a Terminal command
Five steps to clean a Mac, and the lure behind most Mac stealers: a page that asks you to paste a command into Terminal and then type your password.
Where it hides
LaunchDaemons, LaunchAgents, hidden dot files in your home folder, Privacy & Security permissions
Time needed
About 30 to 60 minutes, plus time to change passwords
Built-in help
Gatekeeper, notarization and XProtect stop known malware, not a command you paste yourself
Works on
macOS Sonoma 14, Sequoia 15 and later versions

Need it gone quickly?

Ad: partner link. We may earn a commission if you buy. The steps below work without it.

Can Macs get viruses?

Yes. A classic self-spreading virus is rare on a Mac, but malware is not. Apple itself builds three layers of defense into macOS against it: the App Store, Gatekeeper with notarization, and the XProtect antivirus that detects and removes known malware [1]. Our malware and viruses guide explains the main types on every system.

The big change of the last three years is the info stealer. Atomic macOS Stealer, or AMOS, was first advertised in April 2023 as a Mac stealer with a strong focus on crypto assets [9]. SentinelLabs calls it arguably the most successful malware-as-a-service aimed at Mac users, sold under several names such as Amos, Banshee, Cthulu and Poseidon that behave in much the same way [7].

If your problem is ads, redirects or a search engine that keeps changing, you most likely have adware, and our guide to removing adware from a Mac walks through every step for that. Read on if you ran an installer with strange steps or saw a password prompt you did not expect.

How Mac malware gets in

Almost every Mac infection starts with you running something, so the lure is built to make you step around Gatekeeper.

  • Paste-a-command pages. A site tells you to open Terminal, paste one line and press Return to install an app or fix a problem. Microsoft found MacSync delivered exactly this way, and Sophos traced an AMOS infection in 2026 to the same ClickFix-style trick [5][6]. Our ClickFix guide shows the fake CAPTCHA version of it.
  • Fake app installers. A disk image (DMG) that looks like a real app but asks you to right-click and choose Open. Malwarebytes found Poseidon in a fake Arc browser DMG that used exactly this trick to get past the security checks [8]. Microsoft saw DigitStealer in fake DynamicLake software and AMOS in fake AI tool installers [5].
  • Malicious search ads. Criminals buy ads at the top of search results. In 2024 a Google ad for the Arc browser led to the Poseidon download [8]. In January 2025 a fake ad for Homebrew showed the real brew.sh address but sent visitors to a copy that installed AMOS [12]. In late 2025 ads pointed to poisoned ChatGPT and Grok chats that told users to run an AMOS install command [10].
  • Fake utility sites. Malwarebytes reported a fake CleanMyMac site in 2026 that installed SHub Stealer and backdoored crypto wallet apps [11].
  • Cracked apps. Sophos lists cracked app lures among the main AMOS routes [6]. See why cracked software is a malware risk.
  • Fake alerts in the browser. A page that says your Mac is infected with three viruses is a scam page, not a scan. See how to close the Your Mac is infected with 3 viruses page.

Real Mac malware families

Mac malware you are most likely to meet and how each one arrives
FamilyTypeHow it arrives
Atomic (AMOS)Info stealer sold as a serviceFake app DMGs, Terminal commands, malicious ads, cracked apps [6][9]
PoseidonInfo stealer, AMOS relative [7]Google ads for the Arc browser leading to a fake DMG [8]
BansheeInfo stealer, AMOS relative [7]Fake app downloads and installers
MacSyncInfo stealerCopy-paste Terminal commands [5]
DigitStealerInfo stealerFake DynamicLake app in an unsigned DMG [5]
SHub StealerInfo stealer that backdoors wallet appsA fake CleanMyMac website [11]
CuckooStealer with spyware featuresTrojanized utility apps on download sites

Signs your Mac has malware

  • A password prompt you did not expect, especially right after you ran an installer or a Terminal command. AMOS asks for your Mac password, checks that it is right and saves it to a hidden file [6].
  • A notification that says Background Items Added, naming an app or developer you do not know.
  • New entries under Login Items & Extensions or in the Privacy & Security permission lists.
  • Hidden files with names such as .agent, .mainhelper or .pass in your home folder [6].
  • Accounts acting on their own: password reset emails, new sign-ins, messages you did not send, or crypto that left your wallet.
  • A process with an odd name using CPU or the network in Activity Monitor, or fans running hard at rest.

A stealer often shows no sign at all. It copies what it wants, sends it to the attacker and may delete its own traces [5]. If you ran a suspicious installer or command, treat the Mac as compromised even when it looks normal.

What XProtect and Gatekeeper do, and where they stop

Gatekeeper and notarization form the first layer. Notarization is Apple's malware scanning service for apps outside the App Store, and macOS checks often for revocation tickets so Gatekeeper can block an app Apple has flagged [1]. Apple says these checks run in the background much more often than XProtect signature updates [1].

XProtect is the built-in antivirus. It uses YARA signatures that Apple updates independently from system updates, and macOS checks for them daily by default [1]. When it detects known malware, it blocks it and moves it to the Trash [1]. A message such as will damage your computer, you should move it to the Trash comes from these checks. XProtect also has a behavioral engine for unknown malware and a remediation part, often called XProtect Remediator, that removes known infections already on the Mac [1].

The gap is you. A command you paste into Terminal is run by you, so it does not pass through the Gatekeeper checks an app gets. On Sequoia 15 and later you can no longer skip a Gatekeeper warning with Control-click; you have to approve the app in System Settings > Privacy & Security [4]. If an installer's own instructions take you to that screen or to Terminal, stop. Signatures also follow new variants rather than precede them [7].

Step by step: remove malware from your Mac

1. Disconnect and stop the damage

Turn off Wi-Fi or unplug the cable, so the stealer cannot reach its server. Do not type passwords on this Mac until you finish. Write down the name of the installer or page that started it.

2. Check Login Items and background items

On Sequoia 15 and later, open Apple menu > System Settings > General > Login Items & Extensions; on Sonoma 14 the pane is called Login Items [3]. Remove unknown apps from Open at Login. In the background list, switch off entries with random names, odd developer names or apps you did not install [3].

3. Find launch daemons, agents and hidden files

The adware guide covers the general folder walk. Stealers and backdoors add two habits of their own. First, they often install a launch daemon that runs as root; Sophos found AMOS using /Library/LaunchDaemons/com.finder.helper.plist, a name made to look like part of Finder [6]. Second, they hide the program in your home folder under a name that starts with a dot [6].

  1. In Finder choose Go > Go to Folder and open /Library/LaunchDaemons, then /Library/LaunchAgents and ~/Library/LaunchAgents. Sort by Date Modified.
  2. Select each recent .plist and press Space. The ProgramArguments line shows the program it starts. Note any path that points into your home folder or to a file whose name begins with a dot.
  3. Open your home folder and press Shift-Command-Period to show hidden files. Look for new files such as .agent, .mainhelper, .helper or .pass [6].
  4. Move the .plist files and the programs they start to the Trash, enter your password, then restart.
  5. After the restart, check that the files did not return. If they did, something else is running.

Leave files from Apple, your printer maker, cloud storage, VPN and security software alone. If unsure, search the name in our Mac virus guides before you delete it.

4. Revoke the permissions malware asked for

Open System Settings > Privacy & Security. In each of these lists, switch off or remove any app you do not know:

  • Full Disk Access. Lets an app read Mail, Messages, Safari data and other apps' files.
  • Accessibility. Lets an app click, type and control other apps, which a backdoor can use to approve its own prompts.
  • Screen & System Audio Recording (Screen Recording on Sonoma). Lets an app capture what is on screen, including codes and seed phrases.
  • Input Monitoring. Lets an app read keystrokes.
  • Automation. Lets one app control another, such as a script controlling your browser.
Mock-up of System Settings Privacy and Security showing Full Disk Access, Accessibility, Screen Recording and Input Monitoring with suspicious apps
Four Privacy & Security lists to check after an infection. Switch off any app you do not recognize, such as a helper with no developer or a hidden dot name.

5. Look at Activity Monitor

Open Applications > Utilities > Activity Monitor. On the CPU tab, sort by % CPU; on the Network tab, sort by Sent Bytes. Select a process you do not know and click the Info button, then Open Files and Ports to see the path of the file behind it. A path in your home folder, in /tmp or in a dot folder is a strong sign. Quit it and delete the file as in step 3.

6. Delete the app and the installer

In Applications, sorted by Date Added, drag the fake app to the Trash. Delete the DMG from Downloads, eject any mounted disk image, empty the Trash and restart.

7. Scan the Mac

Reconnect to the internet so XProtect and your scanner can update. Run a full scan with a Mac security tool that has Full Disk Access, so it can read your Library folders. It catches files you missed.

What a Mac stealer takes and what to change

Sophos lists the macOS Keychain, Chrome and Firefox passwords, cookies and session tokens, Apple Notes and crypto wallet data among what AMOS collects [6]. Microsoft adds cloud credentials and developer access keys for the newer stealers [5]. Read more in our info stealers guide.

Chart of data a Mac info stealer takes, such as Keychain, browser passwords, cookies and crypto wallets, with the action to take for each
What Mac stealers copy and what you change for each. Do this from a clean phone or computer, not the infected Mac.
  1. Use a clean device. Change passwords from your phone or another computer until the Mac is clean.
  2. Start with email and your Apple Account, then banks, work accounts and anything saved in Passwords or your browser.
  3. Sign out of all sessions. Stolen cookies let an attacker skip the password, so use each service's sign out everywhere option.
  4. Turn on two-step verification with an app or passkey, not SMS where you can.
  5. Move crypto now. If a wallet app, extension or seed phrase was on the Mac, create a new wallet on a clean device and move the funds. A changed password does not protect a stolen seed.
  6. Change your Mac login password, because AMOS stores it [6].
  7. Revoke SSH keys, API tokens and cloud keys if you are a developer [5].

Our checklist for securing your accounts after malware goes through each account type in order.

When to erase and reinstall macOS

Reinstalling macOS from Recovery does not remove your apps or personal data, according to Apple [2]. So it leaves a stealer's files in your home folder and its daemons in /Library. To get rid of a backdoor you cannot find, erase the Mac first and then reinstall.

  • Erase when files keep coming back after a manual cleanup and a scan, when you found a backdoor or remote access tool, or when you cannot trust the Mac with your work.
  • Back up your personal files first. Do not restore apps or the whole Library, as that can bring the malware back.
  • To reinstall, start up from macOS Recovery, choose the reinstall option, click Continue and follow the instructions [2]. If the installer cannot see your disk, use Disk Utility in Recovery to erase it [2].
  • Afterwards install apps fresh, then copy your files back.

When a Mac scanner helps

Fortect for Mac is the tool we offer on this page. It is a security product built for macOS, with real-time malware defense, browsing and phishing protection, cloud-based detection and a VPN [13]. Its browsing protection helps here, because most Mac stealers arrive through ads and fake download pages. Our Fortect review explains what it covers, how renewal works and how to uninstall it.

We have reviewed two other Mac tools. Intego ONE combines real-time antivirus with an outbound firewall and scored 96.7% Mac malware protection in AV-Comparatives' 2026 Mac test. Combo Cleaner pairs a Mac malware scanner with disk cleanup; removal needs a subscription that renews every six months. Run one real-time scanner at a time.

How to keep malware off your Mac

  • Never paste a command from a web page, chat, search result or AI answer into Terminal unless you understand every part of it. Microsoft and Sophos both point to these copy-paste lures as a main stealer route [5][6].
  • Do not click ads to download software. Type the developer's address yourself, such as brew.sh for Homebrew, because a fake ad can show the real address [12].
  • Treat any installer that asks you to right-click Open, approve it in Privacy & Security or enter your password as a red flag [4][8].
  • Leave automatic updates on, including Install Security Responses and system files, so XProtect gets its daily updates [1].
  • Keep a seed phrase off the Mac entirely: not in Notes, not in a photo, not in a text file.

If you are not sure whether a file or alert is real, ask in our Mac help forum or check the name on the Mac topic page.

Frequently asked questions

Can Macs get viruses?

Yes. True self-spreading viruses are rare, but Mac malware is common, especially info stealers such as Atomic (AMOS), Poseidon and Banshee. Apple builds the XProtect antivirus into every Mac because of it.

How do I know if my Mac has a virus?

Look for a password prompt you did not expect, new Login Items or background items, unknown apps in the Privacy and Security permission lists, hidden dot files in your home folder and accounts that sign in or reset on their own. A stealer can also run without any visible sign.

How do I remove a virus from my Mac for free?

Disconnect from the network, remove unknown Login Items, delete suspicious launch daemons, launch agents and hidden files, revoke permissions you did not mean to give, delete the fake app and restart. Keep automatic security updates on so XProtect can remove known malware.

Does the Mac have a built-in virus scanner?

Yes. XProtect scans apps against signatures Apple updates daily, blocks known malware and moves it to the Trash. It does not stop a command you paste into Terminal yourself, and new variants can slip past it for a while.

I pasted a command into Terminal from a website. What now?

Disconnect from the internet, check for a new launch daemon and hidden files in your home folder, and run a scan. Then change your Mac password and the passwords saved on the Mac from another device, and move any crypto to a new wallet.

Is the Your Mac is infected pop-up real?

No. A website cannot scan your Mac. Close the tab, or force quit Safari and reopen it, and never call the number or install the cleaner it offers.

Does reinstalling macOS remove malware?

Not on its own. Apple says a reinstall from Recovery keeps your apps and personal data, so malware files in your home folder and Library stay too. To remove a backdoor, erase the disk first, reinstall, then restore only your personal files.

Can a Mac stealer take my iCloud Keychain passwords?

AMOS copies the Keychain on the Mac and asks for your Mac password to open it. Assume every password saved on that Mac was taken and change them, starting with email and your Apple Account.

Sources

  1. Apple Platform Security: Protecting against malware in macOS read 2026-10-08
  2. Apple Support: How to reinstall macOS read 2026-10-08
  3. Apple Support: Change Login Items & Extensions settings on Mac read 2026-10-08
  4. Apple Support: Safely open apps on your Mac read 2026-10-08
  5. Microsoft Security Blog: Infostealers without borders: macOS, Python stealers, and platform abuse (February 2026) read 2026-10-08
  6. Sophos X-Ops: Why AMOS matters: The macOS malware stealing data at scale (May 2026) read 2026-10-08
  7. SentinelOne: From Amos to Poseidon, a SOC team's guide to detecting macOS Atomic stealers read 2026-10-08
  8. Malwarebytes Labs: Poseidon Mac stealer distributed via Google ads read 2026-10-08
  9. Malwarebytes Labs: Mac users targeted in new malvertising campaign delivering Atomic Stealer read 2026-10-08
  10. Malwarebytes Labs: Google ads funnel Mac users to poisoned AI chats that spread the AMOS infostealer read 2026-10-08
  11. Malwarebytes Labs: Fake CleanMyMac site installs SHub Stealer and backdoors crypto wallets read 2026-10-08
  12. Bitdefender: Criminals use fake Mac Homebrew Google ads in new malicious campaign read 2026-10-08
  13. Fortect: Fortect for Mac read 2026-10-08

More from the malware guide

What is malware and how to remove itMalware is any program installed on your device without your informed consent to steal from you, spy on you, lock your files or use your computer for someone else's profit. Viruses, trojans, ransomware, info stealers and remote access tools are all kinds of malware. To remove it, scan with an up-to-date antivirus, run an offline scan, clear what it left behind and then secure your accounts from a clean device.Best malware removal tools in 2026Trojans, info stealers, coin miners and rootkits do not all leave through the same door. Some tools block malware before it runs, some scan on demand, some work from outside Windows and some repair what the infection broke. This page matches seven tools we reviewed to those jobs, with prices, free parts and lab results.How to remove a virus or malware from an Android phoneAndroid does not get viruses in the old sense. It gets malicious apps: banking trojans that fake your bank's login screen, spyware and stalkerware, SMS stealers and droppers that hide in ordinary-looking apps. They all depend on a few special permissions. Take those away, uninstall the app in Safe mode, then secure your bank and accounts from another device.Types of malware: what each kind does and how to spot itMalware is not one thing. A file infector, an info stealer and a browser hijacker behave differently, leave different signs and need different fixes. This guide compares 16 types side by side, then explains each one with current examples and what it looks like on a home computer or phone.
5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year