Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesNo: a cracked Mac app or installer is not safe to assume harmless. Kaspersky reported in December 2023 that malicious cracked apps were distributed as PKG installers that could install a Trojan-Proxy on a Mac. The malware could make the infected computer relay someone else’s network traffic. A related investigation found cracked apps carrying a backdoor capable of stealing cryptocurrency wallet recovery phrases.
How the Trojan-Proxy infection works
The infection described by Kaspersky starts when someone downloads and runs a malicious installer disguised as pirated software. It is not an ordinary Mac App Store update. The reported installers were PKG files, a format that can run scripts as part of installation.
- The installer runs its script. The malicious script copies files into Library locations and installs a LaunchAgent, a macOS mechanism that can start software automatically and help it persist.
- Administrator access may be involved. If the installer requests an administrator password and receives it, its script can inherit administrator privileges. A password prompt is not, by itself, proof of infection—legitimate installers can need elevated access—but an unexplained prompt from pirated software is a serious warning.
- The malware locates its command server. Kaspersky says the Trojan used DNS-over-HTTPS (DoH) to obtain a command-and-control (C&C) server address. Because the lookup travels in HTTPS traffic, it can resemble ordinary web traffic.
- The Mac becomes a proxy. The malware connects to the server over WebSocket and supports TCP and UDP connections. That lets an operator route traffic through the infected Mac, using it as infrastructure for someone else’s activity.
Kaspersky’s 6 December 2023 report says the earliest sample it found had been uploaded to VirusTotal on 28 April 2023. The reported samples targeted macOS Ventura 13.6 and later, on both Intel and Apple-silicon Macs. Those details describe the samples in that report; they do not establish the scope of every later campaign or prove that other macOS versions are safe.
Why the risk is more than proxy abuse
A proxy infection can put a Mac’s network connection to use without making the computer’s owner the person directing that traffic. But proxying is not the only risk associated with cracked apps.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
In a related investigation published on 22 January 2024, Kaspersky described a second-stage backdoor delivered through cracked applications. The chain used DNS TXT records to assemble encrypted Python scripts and created LaunchAgents that repeatedly fetched and ran payloads. The final payload could replace installed Exodus and Bitcoin wallet applications with infected versions that stole secret recovery phrases when a wallet was unlocked.
That is a separate, related campaign finding—not evidence that every Trojan-Proxy infection also steals wallet phrases. It does show why a cracked installer should not be treated as a contained nuisance: the installer may be an entry point for additional malicious software.
Rank #2
What can tell you a PKG installer is suspicious?
There is no single visible sign that reliably proves a PKG is infected. A professional-looking installer, a successful installation, or the absence of an error message does not establish that it is safe. Judge the context and the behavior together:
- Where it came from: a pirate site or torrent is a major warning. An app obtained from the Mac App Store or the verified developer’s site is a safer choice than an unauthorized copy.
- What it asks you to do: an unexpected request for an administrator password deserves scrutiny, especially when it comes from pirated software. Do not enter your password just to get a cracked app running.
- What it installs: the reported Trojan copied files into Library locations and installed a LaunchAgent. New or unfamiliar Library files and LaunchAgents after running an untrusted installer are reasons to investigate, but their presence alone does not identify this malware.
- What you can observe: DoH and WebSocket traffic can look like routine HTTPS activity. A quiet Mac or ordinary-looking network use therefore cannot rule out compromise.
The report describes installation behavior, not a reliable end-user checklist of filenames or a guaranteed visual indicator. Avoid deleting unfamiliar system files at random; that can disrupt legitimate software without confirming or removing an infection.
Free tools Windows power users keep installed
One-click scans. No signup required.
What to do if you installed a cracked app
- Stop using the suspected app and disconnect the Mac from the network. This can limit further communication while you decide how to respond; it does not remove the malware.
- Do not enter more passwords on that Mac. If you supplied an administrator password to the installer, treat the machine as potentially compromised rather than assuming uninstalling the app is enough.
- Protect accounts from a separate, trusted device. Change important passwords and review account sessions if you used them on the Mac after the suspected installation. Do not use the possibly compromised Mac to secure your accounts.
- Treat an affected crypto wallet as an urgent case. If Exodus or a Bitcoin wallet was installed or replaced during the suspected infection, or you unlocked a wallet on the compromised Mac, assume its recovery phrase may be exposed. Use a trusted device and seek wallet-provider or qualified incident-response guidance before taking action with the wallet.
- Get the Mac assessed and cleaned. Contact Apple Support or a reputable incident-response professional. Tell them which installer you ran, when you ran it, whether it requested a password, and whether you used any cryptocurrency wallet. Reinstalling or removing the visible app alone may leave persistence or later payloads behind.
How to avoid this kind of infection
Apple’s advice is direct: “Never download unlicensed or ‘pirated’ software from the internet.” Get Mac apps from the Mac App Store or the verified developer’s site, and do not disable security prompts just to run a pirated app. Apple also warns that Trojans are commonly spread through internet downloads and email attachments, advises against opening unexpected app files, and suggests considering a standard account for everyday work rather than using an administrator account routinely.
The risk remains relevant beyond Mac applications. In a 12 March 2026 alert, the FBI warned that free software, games, sports and TV content, movies, and torrented files can carry malware that turns devices into part of residential proxy networks. It recommends avoiding pirated software and using official, trusted application stores.
Rank #4
Apple reported blocking 28,000 illegitimate apps on pirate storefronts in 2025. In a 2026 report, it said it prevented 2.9 million attempts to install or launch illicitly distributed apps during the month before 20 May 2026. These are Apple’s reported enforcement figures, not estimates of how many Macs were infected.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the reports do—and do not—establish
The Kaspersky reports describe particular malware samples, infection techniques, and capabilities. They do not establish a reliable campaign-wide victim count or definitive attribution to a threat actor. The Ventura 13.6-and-later detail applies to the Trojan-Proxy samples Kaspersky reported, not to all malware delivered through pirated software.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

