Moonlock by MacPaw has released its Mid-2026 macOS Threat Report, documenting a rapidly evolving threat landscape where Mac and Windows attacks increasingly run on parallel tracks.
ClickFix remains the top attack method in 2026, tricking users into manually executing malicious terminal commands by posing as system fixes or software updates. Adware still dominates detections at roughly 65% of all macOS threats.
The report highlights Odyssey as the leading stealer malware at 62.7% of stealer detections. New macOS backdoor variants increased by 67% compared to the previous period, and stealer variants grew by 17%.
AI developer tools have emerged as a major new attack vector. Fake AI tools now rank second only to cracked Adobe and Creative Suite installers among the most impersonated app categories. Attackers are packaging malicious binaries as legitimate-seeming AI development utilities to trick developers into downloading them.
Perhaps most concerning: over half of malicious Mach-O uploads were digitally signed, and 22% carried valid or recently revoked Apple Developer certificates. This means a significant portion of macOS malware slips past Gatekeeper’s first prompt because it appears to come from trusted developers.
“Apple certified” does not mean safe, the report warns. The same servers, domains, and operators that serve Windows malware now deliver Mac variants, making cross-platform threat hunting essential for security teams.