Skip to main content
Patrick Wardle

Patrick Wardle

Software analyst

Sep 9, 2026

6:02
Like it, it's kinda another business and I'm not sure how to reach them out to talk about [laughs] is it profitable or not.
6:11
not.It's, it's a very gray area too, because I remember, I think it was Malwarebytes that got sued by one of the adware companies 'cause they, like, flagged their adware as, like, malware or un- And it was like, well, the user clicked through the EULA and said, "I agree to install this plugin that will, you know, show me pop-ups." So the adware companies are like, "Legally we're not doing anything wrong here." And so it's this really weird gray area, and now I think they're just labeled potentially unwanted products, PUPs.
6:39
Um, but again, this was, like, something that was, I think, discussed a lot more, a lot more prevalent five plus years ago, where it might still be around, uh, to Kseniia's point, but, you know, I think stealers and those kind of things are, uh, at least in my opinion, impacting everyday users more dramatically as well.
6:59
Because that's the other thing, adware, it's annoying and it, yeah, it can be problematic and should be removed and deleted and prevented, but oh, you get hit by a stealer, like, man, that's can be super gnarly.
7:10
It's like all your accounts overnight are just like poof, your crypto's gone, whatever.
7:14
And so more f- more feasible or more profitable perhaps for the adversaries, and more impactful for the users, so there's a lot more discussion, uh, around them.
7:21
But also they seem to be more prevalent regardless.

10 MINS LATER

17:16
Do you wanna give a little glimpse into any talks that you guys are presenting or are looking forward to in November?
5:56
no no please go ahead um i was just gonna say i really wish apple would let their researchers and engineers go on podcasts like that's like the one gripe i've had with them for a while i'm like if they could just have them on a podcast just trust them to not reveal anything they're not supposed to reveal i feel like that'd be so beneficial to just have like pr like have pr on the security side of things i don't know i would what do you think about i
6:22
would love that i and perhaps naively pessimistic, but you know, Apple runs a very tight ship and I think their image is super important.
6:32
I think engineers and researchers, and I include myself in this, I have previously worked at companies and they have threatened to send me to PR training because sometimes the truth is maybe not the most tactical thing to say, uh, most tactful thing to say.
6:49
Uh, so, you know, I understand both sides, but from somebody on the outside who, uh, really thinks that bidirectional communication channel with Apple would be incredibly beneficial for the community.
7:02
I agree 100% that it would be really great to get their security researchers on.
7:06
And then I think it also would give them the opportunity to explain what they're seeing.
7:10
So for example, the bounty program, we are kind of picking on Apple here saying, hey, you did some good things, but there's definitely some negative things here.

7 MINS LATER

14:45
yeah I guess my train of thought is like do you see like less skilled attackers using that and reverse engineering those samples to come up with like better evasion techniques
41:53
Yeah.
41:54
That's the dream.
41:55
In some cases, that's actually the case.
41:57
Some of the older samples were Java-based originally for Windows.
42:00
But Java, at least on paper, is right once run anywhere.
42:04
So we see basically two types of Mac malware coming from other platforms.
42:09
And the first is ones that were written with cross-platform frameworks to begin with.

6 MINS LATER

47:55
So what are the design choices or what's the approach that Apple's taken that you're alluding to that have actually made that malware creation more difficult or pushed more of that work onto the user?
42:01
Mm
42:01
... is write one, write once, run anywhere.
42:04
So we see basically two types of Mac malware coming from other platforms, and the first is ones that were written with cross-platform frameworks to begin with.
42:13
Uh, so things like Electron, um, things like Java, if we're going kind of further back, 'cause Mac used to support, uh, Java.
42:20
So those malware samples largely just had to be recompiled.
42:23
Uh, it's always a little bit more complex than that, but conceptually.
42:26
The other thing we saw is, though, hackers taking their existing Windows capabilities and rewriting them in Swift or Objective-C, some Apple-specific language, and then also kind of implementing the Apple-specific techniques.

23 MINS LATER

65:32
What's something that you would love developers to keep in mind?
41:53
Yeah.
41:54
That's the dream.
41:55
In some cases, that's actually the case.
41:57
Some of the older samples were Java-based originally for Windows.
42:00
But Java, at least on paper, is right once run anywhere.
42:04
So we see basically two types of Mac malware coming from other platforms.
42:09
And the first is ones that were written with cross-platform frameworks to begin with.

6 MINS LATER

47:55
So what are the design choices or what's the approach that Apple's taken that you're alluding to that have actually made that malware creation more difficult or pushed more of that work onto the user?

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.