The FireAI Security Blog

By FireAI Security & Research Team · Published

Spyware on a Mac: How to Spot It, What Removes It, How to Keep It Out

Spyware on a Mac: How to Spot It, What Removes It, How to Keep It Out

“Spyware” covers three quite different things on a Mac, and the right response to each is different. Lumping them together is how people end up buying the wrong tool or, worse, taking a step that puts them in more danger. This article separates the three, lists the signs that are actually worth looking for, points to the removal paths that reputable sources recommend, and then says where a per-app firewall like FireAI fits and, just as clearly, where it does not. FireAI does not detect spyware on disk and does not remove it.

Three kinds of spyware

Stalkerware is commercial software installed by someone who has, or had, access to your Mac and your password: a partner, a family member, an employer. The Coalition Against Stalkerware, founded in 2019 by domestic-violence organisations and security companies, defines it as tools that “enable someone to secretly spy on another person’s private life”, running hidden and without the affected person’s consent. It is often sold under the label of parental control or employee monitoring, and it reports back to whoever installed it.

Infostealers are the opposite in every way: automated, impersonal and fast. They arrive as a cracked app, a fake update or a download promoted through a search ad, ask for your login password in a convincing dialog, copy browser passwords, cookies and wallet files, upload the bundle in one burst and often delete themselves. There is no ongoing surveillance to notice; the damage is done in seconds.

Mercenary spyware is the rarest and the most capable. Apple’s page on threat notifications describes these attacks as “exceptionally well funded” and “vastly more sophisticated than regular cybercriminal activity”, historically associated with state actors and companies such as NSO Group, whose Pegasus tool the Citizen Lab has documented in detail, and aimed at journalists, activists, politicians and diplomats. Apple states plainly that “the vast majority of users will never be targeted”.

The signs that actually mean something

Most lists of “signs your Mac is infected” are padded with symptoms (slowness, heat, a hot battery) that describe nearly every Mac with a browser open. Modern spyware is designed to be quiet, and the useful signs are structural rather than performance-related:

  • Permissions you did not grant. Open System Settings, Privacy & Security, and read the Accessibility, Input Monitoring, Screen & System Audio Recording, Full Disk Access and Microphone lists, which Apple documents in Change Privacy & Security settings on Mac. Stalkerware needs these to log keys and capture the screen, and a name you do not recognise in those lists is the single most concrete sign there is.
  • Items that start on their own. In General, Login Items & Extensions, Apple lists apps that open at login and apps allowed to run in the background. Anything you did not add belongs on your list of questions.
  • Configuration profiles or device management you did not enrol in, visible under Privacy & Security, Profiles.
  • Browser extensions you did not install, and a changed default search engine.
  • A threat notification from Apple, delivered by email to your Apple Account address and as a banner on account.apple.com after signing in. Apple says these are high-confidence alerts; it also warns that it never asks you to open a link or install anything in them.
  • Outbound connections from a process you have never heard of, especially at login or on a fixed schedule. This is where a network monitor earns its place, and it is the sign the other five cannot show you.

One more caution about signs: absence of evidence is not evidence of absence. A Mac with clean permission lists and no unknown login items can still have been hit by an infostealer that finished its work and deleted itself weeks ago, which is why a password manager, unique passwords and two-factor authentication on every account matter more than any after-the-fact check. If you find any of the signs above, change your passwords from a different device before doing anything else on the suspect Mac.

What Apple provides

Two Apple mechanisms are directly relevant. Lockdown Mode, available on macOS Ventura and later, is a deliberate trade of convenience for attack surface: most Messages attachment types are blocked, complex web technologies are disabled, FaceTime calls from people you have not called recently are refused, wired accessories require the Mac to be unlocked, and configuration profiles cannot be installed. Apple describes it as being for people who face “extremely rare and highly sophisticated” attacks, and when the Citizen Lab reported the BLASTPASS exploit chain in 2023, both it and Apple said they believed Lockdown Mode blocked that particular attack.

The second is XProtect, which Apple’s Platform Security Guide describes as detecting and removing known families of hostile software when they launch or when new signatures arrive. That covers infostealers and stalkerware products Apple has already catalogued, silently, and it is why keeping macOS updated is the first and cheapest prevention step. It does not cover a product Apple has not yet added a rule for.

How to check, and what removes it

For a first, free look at what is set to run persistently, the non-profit Objective-See Foundation’s KnockKnock lists launch agents and daemons, login items, browser extensions, cron jobs and other persistence locations, shows each item’s code-signing status and can check them against VirusTotal. It answers the question “who is there?” rather than removing anything, which for a stalkerware case is often exactly what you want before deciding what to do.

For removal of known spyware and infostealer families, Malwarebytes for Mac offers a free scanner that the company describes as a clean-up tool for infections that have already happened. For anything you cannot identify or clean, Apple Support is the right first call, and the last resort Apple documents is a clean reinstall of macOS from Recovery after backing up your files, then restoring only documents, not apps, from that backup.

Two cases need a different order of operations. If you suspect stalkerware installed by someone close to you, the Coalition Against Stalkerware and domestic-violence organisations advise thinking about safety before removal: removing the software alerts the person who installed it, and evidence on the machine may matter later. If you receive an Apple threat notification, Apple’s own advice is to enable Lockdown Mode, update every device, and contact the Access Now Digital Security Helpline, a free, round-the-clock service for people at risk. Mercenary spyware is a job for forensic specialists, not a scanner.

Keeping it out

Prevention is mostly a short list of habits that Apple’s own documentation supports. Install updates the day they ship. Do not override Gatekeeper to run an app from an unknown developer; Apple’s support page on that dialog calls doing so the most common way a Mac gets infected. Never type your login password into a dialog raised by an app you just downloaded. Use a separate, standard (non-administrator) account for daily work. Review the Privacy & Security permission lists every few months, and remove what you do not use. If your work puts you at risk, turn on Lockdown Mode and accept the friction.

The step none of those cover is the network. Every kind of spyware, from the cheapest stalkerware product to Pegasus, has to report to someone, and it does so through an outbound connection from a process on your Mac. A per-app firewall puts that step in front of you. In FireAI, an app that has never connected before gets a permission prompt with the on-device model’s reason, so a monitoring tool installed while you were away is not able to phone home silently the first time. Its threat-intelligence feeds (abuse.ch, Spamhaus, Phishing Army, OpenPhish, FireHOL and the current Tor exit nodes) refuse known hostile destinations locally, without your traffic leaving the Mac. The Paranoid mode blocks unsigned apps, telemetry and trackers by default, and the live map shows where every connection goes, which is a fast way to notice an unfamiliar process talking to an unfamiliar country. The unencrypted data guard stops a card number, password or API key leaving over plain HTTP, which is how some cheaper stalkerware still reports.

The limits deserve the same clarity. FireAI does not scan files, does not detect spyware on disk and does not remove anything. Spyware that hides inside an app you have already allowed, or that sends encrypted traffic to a destination with a clean reputation, is not distinguished from ordinary traffic. Mercenary spyware that runs inside a system process inherits that process’s permissions. A firewall gives you visibility into the one step spyware cannot skip; removal is the job of the tools and people named above, and prevention starts with the account, update and permission habits that cost nothing at all.

How FireAI and HisnLabs fit in

FireAI does not find or remove spyware; what it gives you is the one signal every spyware family shares, the moment an unfamiliar process on your Mac tries to report to someone, with the choice to say no.

FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its Autopilot feature) on real traffic patterns, all without any of it leaving your Mac.

You can read the technical decisions behind it, or try FireAI for 17 days, at FireAI, by HisnLabs.

Sources