Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Banshee Stealer was a macOS information-stealing malware offered as a paid service in 2024. Its source code leaked on November 23, 2024, and its author reportedly shut down the public service the next day. That did not immediately end distribution: Check Point observed phishing campaigns delivering an updated variant after the shutdown, and later researchers described a Rust sample with similar behavior. The available reporting does not establish whether the original operators or a currently attributable campaign remain active as of October 4, 2026.

What Banshee Stealer was designed to do

Banshee targeted macOS systems, including both Intel x86_64 and Apple silicon ARM64 architectures in the sample analyzed by Elastic Security Labs on August 15, 2024. It was an infostealer: malware built to collect sensitive information from an infected computer and send it to an attacker.

Elastic’s analyzed sample sought system information, browser data, cryptocurrency wallet information, and other files. It could also display a deceptive password prompt and collect a user password. The specific findings apply to the sample Elastic examined; they do not prove that every Banshee build collected every listed data type.

  • Browser information: credentials, history, and cookies from browsers including Chrome, Firefox, Brave, Edge, Vivaldi, Yandex, Opera, and Opera GX; Safari cookies were handled separately.
  • Other sensitive data: keychain-related data, Notes data, selected document and key file types, and cryptocurrency wallet information.
  • Extension targeting: Elastic reported that the sample targeted roughly 100 browser extensions.

Check Point Research also described theft of credentials and sensitive files. The two reports show why the malware mattered to Mac users: its targets included information that could expose online accounts, personal documents, and cryptocurrency holdings.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the reported $3,000 monthly price means

Banshee was advertised as malware-as-a-service: a subscription offer that let customers use the malware rather than develop it themselves. The often-cited “$3,000 a month” is a useful approximation, not one fixed price documented across every sales channel.

Report and timing Channel and offer Reported price
Elastic Security Labs, August 15, 2024 Reported subscription price $3,000 per month
Check Point Research, retrospective published January 9, 2025 Telegram listing $2,999
Check Point Research, retrospective published January 9, 2025 Later discounted offer on XSS and Exploit forums $1,500 per month

The figures describe reported offers, not verified transaction totals or proof of how much the operators earned. The lower forum price was specifically described as a discount.

How Banshee’s development and leak unfolded

August 2024: technical analysis and commercial offers

Elastic published its analysis on August 15, 2024, documenting a macOS stealer supporting Intel and Apple silicon systems and reporting a $3,000 monthly subscription. Check Point’s later account described a Telegram offer at $2,999 and a discounted monthly forum offer at $1,500.

September 2024: a variant reused an XProtect-associated method

Check Point says it first found a Banshee version using string encryption on September 26, 2024. The method reused the algorithm Apple uses in XProtect, Apple’s built-in malware protection. That is code reuse; it does not make Banshee an Apple product, nor does it mean Banshee defeated every Mac security protection.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check Point reported that the version it examined had gone undetected by most antivirus engines for more than two months. This is Check Point’s finding about that sample and its observations—not a claim that all security products failed or that all Macs were exposed.

November 2024: source code leaked and the public service closed

Check Point dates the source-code leak to November 23, 2024, when it appeared on XSS forums. The report says the author closed the public service the following day. Check Point also observed phishing campaigns distributing an updated variant after the closure.

The leak therefore had two implications. Security vendors could use the published code to improve detections for original and updated versions, but other actors could also study or adapt it. Publication of the source did not itself erase existing copies or stop every campaign using the malware.

January 2025: a similar Rust sample was reported

On January 31, 2025, Iru described a Rust-based infostealer sample with behavior and targets similar to leaked Banshee. Iru assessed it as a likely rewrite, but noted that its delivery to localhost suggested it might be a test or prototype. The report is evidence of a related-looking sample, not confirmation that the original Banshee service returned or that this sample was deployed against victims.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What later reporting says about activity

Moonlock Lab reported that Banshee accounted for 1.1% of its stealer detections in the first half of 2026. This is a figure from Moonlock Engine’s proprietary telemetry, not a global infection rate, a share of all Mac users, or a victim count. It also does not identify who was behind the detections.

Moonlock separately reported a 67% rise in new macOS backdoor variants and a 17% rise in stealer variants in its tracking through 2025. Those are Moonlock’s measurements of variants it tracked, not universal counts of malware or proof of Banshee’s prevalence.

As of October 4, 2026, the reporting cited here does not resolve whether the original Banshee operators or a currently attributable Banshee campaign remain active. A leak, a service shutdown, and later detections are different events; none alone establishes the operators’ current status.

Practical steps for Mac users

The reports do not provide a complete consumer cleanup procedure for Banshee. For general prevention, Check Point recommends keeping operating systems and applications updated and treating unexpected links cautiously. Moonlock’s general macOS guidance also warns against pasting commands into Terminal or Script Editor simply because a website, video call, or document tells you to.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Install macOS and application updates through trusted, official update mechanisms.
  • Be cautious with unsolicited links and requests to download or run files.
  • Do not run Terminal or Script Editor commands supplied by an untrusted source.
  • If you suspect a work Mac is infected, contact your organization’s security team. For a personal Mac, seek help from a qualified incident-response professional rather than relying on these general prevention tips as a cleanup plan.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.