Antivirus software developer Malwarebytes today shared its State of Malware Report for 2020 [PDF], which suggests that Mac malware is growing much more common.

For the first time ever, Macs outpaced Windows PCs in the number of threats detected per endpoint. Malwarebytes detected 11 threats per endpoint for its Mac users, compared to 5.8 for its Windows users. The Mac threats were up quite a bit from the 4.8 threats detected per endpoint in 2018.

macmalwaredetectionsperendpoint
Malwarebytes says that there was a 400 percent increase in the overall prevalence of Mac threats in 2019, but part of that increase is attributable to an increase in the Malwarebytes for Mac user base, which is why the threats per endpoint metric was used for comparison purposes. Malwarebytes claims that the average number of threats detected on a Mac has surpassed Windows "by a great deal."

This means that the average number of threats detected on a Mac is not only on the rise, but has surpassed Windows--by a great deal. This is likely because, with increasing market share in 2019, Macs became more attractive targets to cybercriminals. In addition, macOS' built-in security systems have not cracked down on adware and PUPs to the same degree that they have malware, leaving the door open for these borderline programs to infiltrate.

This data only includes threats detected by the Malwarebytes software, of course, and it is limited to Mac users who have Malwarebytes installed. Many Mac users may not install antivirus software like Malwarebytes until there's a sign of something wrong, so it's important to take that into account when viewing these numbers.

Adware overall was more aggressive in 2019, targeting consumer and business endpoints on Windows, Mac, and Android devices. There were a total of 24 million Windows adware detections and 30 million Mac detections, with the top consumer threat detections belonging to adware families.

According to Malwarebytes, the Mac threats appeared at the top of its overall threat detections for the first time. The number one Mac threat detected was a family of adware called NewTab, installed as a browser extension or as an app. NewTab aims to redirect searches on the web to earn illicit ad revenue.

topmacdetectionsmalware2019
Most Mac threats are not as dangerous as some of the threats detected on Windows machines and consist of adware and potentially unwanted programs. The most common traditional Mac malware family, OSX.Generic.Suspicious was far down on the list of Mac-specific malware detections in the 30th spot.

Potentially unwanted programs include "cleaning" apps like MacKeeper and MacBooster, along with apps like Advanced Mac Cleaner, Mac Adware Cleaner, and others. Of all Mac threats, only one incident used a technique other than tricking the user into downloading and opening something they shouldn't.

That is the incident in which Coinbase, and several other cryptocurrency companies, were targeted with malware that infected systems through a Firefox zero- day vulnerability. Affected systems were infected with the older Wirenet and Mokes malware. This was the first time such a vulnerability had been used to infect Macs in any significant way since 2012, when Java vulnerabilities were used repeatedly to infect Macs (until Apple ripped Java out of the system, ending the threats).

According to Malwarebytes, adware and unwanted problems are becoming a more noticeable nuisance to Mac users overall, and Mac users can "no longer say that their beloved systems are immune from malware."

Malwarebytes' full report can be read on the Malwarebytes website.

Top Rated Comments

farewelwilliams Avatar
75 months ago
Would prefer an independent study. Perhaps Malwarebytes realizes their PC sales have saturated but Mac remains untapped.
Score: 16 Votes (Like | Disagree)
NickName99 Avatar
75 months ago

Would prefer an independent study. Perhaps Malwarebytes realizes their PC sales have saturated but Mac remains untapped.
Agreed, this kind of looks like an advertisement for Malwarebytes.
Score: 12 Votes (Like | Disagree)
farewelwilliams Avatar
75 months ago

don’t be so paranoid. Honest question. Would you believe anyone that would present data that comes to a conclusion that is against your current belief of mac security?
I would have to look at the data and where the data came from before making judgements like any sane human being.

I mean, this stuff has been going on for decades. Cocacola sponsors many scientific studies. They get to review the results and squash any report that makes Cocacola look bad and release the ones that make them look good. Companies with an interest in oil are releasing scientific reports that electric vehicles emit more carbon into the air (indirectly by electricity generation from coal) than gas vehicles which is simply not true. Do I need to go on?

Keep in mind, I never said "THEY ABSOLUTELY RELEASED FAKE DATA". I simply said I would prefer the data to come from an independent company.
Score: 8 Votes (Like | Disagree)
Naraxus Avatar
75 months ago

Would prefer an independent study. Perhaps Malwarebytes realizes their PC sales have saturated but Mac remains untapped.
And of course is immediately discredited in your eyes, never mind that a company who's business is to protect against malware would be perhaps the most knowledgeable about malware threats :rolleyes:
Score: 6 Votes (Like | Disagree)
ytk Avatar
75 months ago

Could you elaborate on this one?
Just cleaned out a system that had malicious profiles installed the other day. There is a pane in System Preferences called “Profiles” that contains a bunch of, well, profiles. It's normally not visible, and I'm honestly not sure whether it's a legitimate pane or something installed by malware. In any case, it somehow allows the OS to control certain aspects of various applications; in this case, it set the default search engine for Google Chrome to some adware site. Attempts to change that setting in Chrome failed, with Chrome stating that the search engine setting was enforced by the network administrator. Anyway, after deleting all of the “profiles” in the Profiles pane, the search engine enforced setting was released, and I was able to reset it to the default of Google (so much for eliminating adware…). Interestingly, once the profiles were all removed, the Profiles pane disappeared from System Preferences.

The insidious part is that there was also apparently a startup .plist that installed a new copy of the profile; I'm guessing that is the reason why I saw the same profile installed 8 or 9 times (once for every reboot since the malware had been activated). I only discovered that because I decided to install and run Malwarebytes, which I have to say did its job in this case, and for free at that (they charge for continuous monitoring or something, but the free version is perfectly adequate for detecting and removing malware). Malwarebytes was able to detect and remove the malicious .plist, and I'm reasonably confident that it was purged from the system entirely.

Not trying to sound like a shill for Malwarebytes here, but I was actually pretty impressed. I wouldn't pay for it myself, but I can see paying for a subscription for someone who is less computer-savvy, if only so you don't have to spend time cleaning crap like that out on the regular.
Score: 6 Votes (Like | Disagree)
danielwsmithee Avatar
75 months ago
This doesn’t surprise me at all. I’m actually surprised the numbers aren’t even higher for Macs.

Most of the Mac users I know only install a Mallware removal tool if they suspect they are already infected.

Most of the windows users I know install one by default.

I would expect the number of threats per end point to be significantly higher due to this behavioral difference.
Score: 5 Votes (Like | Disagree)

Popular Stories

sam sung auction

Former Apple Employee Sam Sung Changed His Name to Avoid Attention

Wednesday October 22, 2025 4:44 pm PDT by
Back in 2012, an Apple retail employee named Sam Sung went viral because his name is similar to Samsung, one of Apple's main competitors. In a recent interview with Business Insider, he detailed that period in his life, how Apple responded, and he explained why he ultimately changed his name. Someone posted an image of Sung's Apple business card on Reddit in 2012, and it spread rapidly....
iOS 26 Battery Glass Feature

iOS 26.1 Beta Liquid Glass Battery Drain Test: Tinted vs Clear Mode

Friday October 24, 2025 2:30 pm PDT by
In the fourth iOS 26.1 beta, Apple added a "Tinted" option that reduces the translucency of Liquid Glass for those who prefer a more opaque look. I saw some comments wondering whether the setting might preserve battery life, so I thought I'd do some testing. Test Settings I did four separate tests using the iPhone 17 Pro Max, and I kept the parameters as similar as possible. Here are the...
iOS 26

iOS 26.1 Coming Soon With These 8 New Features for Your iPhone

Wednesday October 22, 2025 6:15 am PDT by
The upcoming iOS 26.1 update includes a handful of new features and changes for iPhones, including a toggle for changing the appearance of the Liquid Glass design, "slide to stop" for alarms in the Clock app, and more. iOS 26.1 is currently in beta testing. The update will likely be released in the first half of November, and it is compatible with the iPhone 11 series and newer, but some...
All Screen iPhone 2027 Feature 1

Report: Apple to Skip 'iPhone 19' Name for 'iPhone 20'

Thursday October 23, 2025 4:28 am PDT by
Apple's new iPhone lineup launched in the fall of 2027 will be called the "iPhone 20" models, rather than the "iPhone 19," according to research firm Omdia. Speaking at a conference in Seoul (via ETNews), Omdia Chief Researcher Heo Moo-yeol corroborated rumors that Apple plans to move the launch of its standard iPhone to the first half of the year and provided some additional clarity about...
trump white house ballroom

Apple Donating to Trump's $350M White House Ballroom Project

Thursday October 23, 2025 3:55 pm PDT by
Apple is one of several tech companies that will contribute to the construction of U.S. President Donald Trump's 90,000-square-foot ballroom, reports CNN. Construction began on the ballroom this week, and the White House's east wing was torn down. Trump claims that the ballroom will cost $350 million, and that it will be privately funded through donations. The cost has already increased $150 ...
apple wallet drivers license feature iPhone 15 pro

iPhone Driver's License Feature in Apple Wallet App Launches in Another U.S. State

Thursday October 23, 2025 7:44 am PDT by
In select U.S. states, residents can add their driver's license or state ID to the Wallet app on the iPhone and Apple Watch, providing a convenient and contactless way to display proof of identity or age at select airports and businesses, and in select apps. Starting today, the feature is available to residents of West Virginia. To set it up, open the Wallet app and tap on the plus sign in...
cadillac lyric infotainment

GM to Remove CarPlay from All Future Vehicles, Including Gas Cars [Updated]

Wednesday October 22, 2025 11:34 am PDT by
General Motors began phasing out support for CarPlay in its electric vehicles back in 2023, leading to complaints from iPhone users, but the company has no plans to back down. In fact, GM is going further and plans to remove CarPlay from all future gas vehicles, too. In an interview with The Verge, GM CEO Mary Barra said that the company opted to prioritize its platform for EVs, but the...
iPhone Air

Report: 'Virtually No Demand' for iPhone Air

Wednesday October 22, 2025 3:22 am PDT by
Apple is "drastically" cutting production of the iPhone Air and shifting focus toward the iPhone 17 and iPhone 17 Pro models, Nikkei Asia reports. The business publication claims to have learned of a major cut to iPhone Air production motivated by weaker-than-expected consumer interest, nearly to "end of production levels." Despite early reports of the iPhone Air selling out within hours of...
maxresdefault

Apple's iPhone Air Experiment Fails as Supply Chain Cuts Production by 80%

Wednesday October 22, 2025 10:48 am PDT by
iPhone Air demand failed to meet Apple's expectations and the company's supply chain is scaling back shipments and production, reports Apple analyst Ming-Chi Kuo. Subscribe to the MacRumors YouTube channel for more videos. Suppliers are expected to reduce capacity by more than 80 percent between now and the first quarter of 2026, and some components with longer lead times will be discontinued ...