How to Protect Your Mac From Malware and Ransomware

XProtect checks for new malware signatures every twenty-four hours, silently.

By Kristina Terech - Staff Writer
6 Min Read

Avoiding malware is a result of both preparation and ongoing vigilance and consistent behavior.

Apple’s built-in protections

Early in macOS’s history, Apple took a hands-off approach to malware, working to keep the system as free of exploits as possible, but leaving viral issues to third parties. That changed in Mac OS X 10.6 Snow Leopard, when Apple added the first vestiges of XProtect, its file quarantine and anti-malware checker. It now has several often interlocking measures.

Like Gatekeeper, you won’t find the name XProtect in macOS at all; Apple describes it only on their website.

Apple continues to add invisible and overt protections, too, such as the anti-paste warning and script blocker described in the kinds of Mac malware.

XProtect and XProtect Remediator

XProtect offers just a single aspect of anti-malware software, which is that it protects against known exploits. Using a method that relies on a signature that identifies specific malware, XProtect from macOS 10.15 Catalina onward checks apps when first launched or after they’ve been modified, and whenever the list of signatures updates. Apple collects these signatures into a database; a scheduled process automatically checks every 24 hours for updates to it. Apple will make emergency pushes to your Mac sooner if necessary. If a compromised app is found, you’re alerted to take action.

The moment an exploit is found in the wild, these XProtect updates ensure no Mac user connected to the internet after that point will be subject to the attack, even as Apple releases operating system security software fixes that take longer typically to ship that prevent future variant attacks that rely on the same weakness.

Apple used to also schedule regular passes by the hidden Malware Removal Tool (MRT), which could both find and remove malware, including in documents. Because Apple provides only limited documentation about XProtect and didn’t even mention MRT, it’s hard to know how they interact. Fortunately, Mac users have the previously mentioned Howard Oakley, one of the key independent people who finds and documents hidden system-level features.

Howard discovered Apple had added a new tool called XProtect Remediator that runs frequently and can both discover and remediate (take action on) any malware it finds. Howard reported in 2022 that Apple sunsetted MRT and now relies entirely on Remediator—including in macOS back to Catalina—which scans about once a day generally, although individual modules may run more frequently. In a post in June 2023, Howard explained the replacement and listed current modules that Remediator uses to check for known malware.

Check Howard’s site for updates about XProtect and Remediator if that piques your interest. Or get his free tool, SilentKnight, to get detailed information about scans and fixes installed on your Mac.

Gatekeeper

Gatekeeper is a great way to prevent potentially dangerous software from launching, even when you’ve been fooled into downloading a file you think is legitimate. Likewise, configuring Gatekeeper to App Store only for accounts you manage for other people—kids and others who want you to help them stay out of trouble—limits their potential exposure even more.

System extensions

The macOS system can be modified by extensions, as covered in what launches on your Mac, which includes modifications to and monitoring of network traffic. Even third-party software that’s notarized and signed has to declare to Apple what kind of networking it’s engaged in. Thus, a virus that somehow managed to insert itself into legitimate, signed software would still be unable to tap into your networked data without alerting you or causing errors.

Security responses

Starting in macOS 13 Ventura (and iOS 16/iPadOS 16), Apple added Rapid Security Response, a new method for delivering critical security updates without requiring a full system update. Starting in Golden Gate, macOS seemed to encompass those responses in the “Install system data files and security updates” setting in Automatic Updates; see how to set up automatic security updates. All the items in this category are installed automatically and don’t require a reboot.

Apple’s array of protections, described in how macOS protects its own system files, prevents malware from changing them.

Keep good backups

The easiest way to fight malware of all kinds, and particularly ransomware, is to have a continuously streaming backup of your documents, along with an archive or version history.

Ransomware attacks occur at some specific point in time, and most of them aren’t subtle: they try to encrypt all potential files as fast as possible to avoid detection. While some malware can try to erase backups or you might discover it was installed months ago, ransomware requires a much shallower archive.

If you have any or all of the following, you can use anti-malware software to remove the ransomware; tune up your system to avoid future attacks; and then restore files:

  • Time Machine: Time Machine backups retain file versions as they’re modified, and updates are typically written every hour. Older files are typically deleted only after a few weeks and only when there’s pressure on available storage. You may be able to roll back your corrupted files to a snapshot just before the attack began.
  • Cloud backups: Backblaze and other incremental archiving services typically run continuously or frequently, and retain overwritten and deleted files for a period of time, usually no less than 30 days. Some services let you pay extra to retain files for up to one year or as long as forever—as long as you keep paying. Using the service’s tools, you can find the point before the attack and download an archive of pristine files.
  • Sync services: Services like Dropbox and others sync files as you modify them while retaining previous versions and deleted files, just like cloud backups. It can be a little trickier to grab all files from a point in time, but it’s doable.
  • Occasional offline clones: Obviously, if you clone your drive after a ransomware attack, the cloned version has the same problem as your live system. However, making regular clones that you store offline (not connected or powered up), or even offsite, can give you a revert position if you have a problem with other backups, even if you might lose some more recent file changes or email messages.

Backblaze stopped archiving cloud-based files available through the macOS filesystem, such as Dropbox, Google Drive, and Microsoft OneDrive, in April 2026. Some people were upset about this, because Backblaze provided this detail in an update log for its apps rather than in an announcement. It’s not in a support note, either.

The reason, however, is straightforward: Apple shifted how cloud sync services appear in macOS to the Finder, apps, and parts of the system. The files appear locally stored, while sync service components ensure they load a file on demand if there’s no cached copy.

For backup services, that’s problematic, because it either means every synced file is loaded, which causes delays and huge bandwidth usage, or a stub is stored, which isn’t useful for restoring. Backblaze opted out, since it can’t reliably ensure it’s copying your cloud files.

So what are you to do as a user? The reason to use the cloud is to not store files locally. I don’t want to—and don’t want you to—rely on the potential that just a single copy of your files exists in the cloud. I haven’t figured out the answer yet. Carbon Copy Cloner and other tools have a way you can temporarily download files from the cloud to back them up, but there are complications involved in this, too, as Bombich Software explains in a detailed note for CCC.

Common sense

As with everything in the world of security, all you can do is improve your odds. So, when it comes to malware, here are my recommendations. First, everyone (regardless of risk level) should do the following:

  • Install security updates rapidly: Apple pushes XProtect Remediator updates to your Mac and Rapid Security Responses, but you need to choose to install or set automatic installation for most security updates. Apple will often put out the word if there’s a really severe problem. See how to set up automatic security updates.
  • Trust your gut when it says “no”: If you receive an email that wants you to carry out an action, give it a few looks before proceeding. Don’t click unknown URLs. If you reach a site with a weird or dubious URL, close the tab immediately. Don’t enter your administrator password when you don’t know why it’s being asked.

I’m not waggling my finger at you—I’ve missed my gut talking, too. Recently, a spate of “unpaid toll camera fee” and “unpaid traffic ticket penalty” texts spewed in my and many people’s text messages. Since we have a toll bridge near us, I thought, “Oh, something must have gone wrong with the account.” But I checked the account first instead of clicking the link. That saved me.

Apple and third-party password managers keep you from falling into a phishing abyss. If you saved a password or passkey at americanexpress.com and go to amer1canexpr3ss.com, the manager won’t cough up the credentials. Keep a close eye on this, as sometimes companies have multiple sites for different services or tasks, and you may occasionally have to use your credentials at a different domain.

  • Filter your mail: Email is one of the most common ways for malware to spread, and a good spam filter will zap it before it hits your inbox—or before you’re as naïve as I am sometimes!

Even if your email provider offers effective, configurable server-side filtering, I recommend adding SpamSieve.

  • Avoid software whose origins you don’t know: Malware often spreads through sketchy or pirated software. If you don’t know who made an app or where it came from, or you know it should be paid for, but you’re nevertheless downloading a cracked or otherwise non-legitimate version, you are asking for trouble.

Firewalls and network monitoring

At one point we both avidly recommended using firewall software. Apple’s built-in solution is fairly weak, so we’d suggest one of several third-party options, often bundled with anti-malware software. Up until a few years ago, it seemed like the biggest risk to a Mac user would be from a remote invader.

Turns out, not! Phishing, Trojan horses, stolen or misused developer certificates, and simple “hey, install this by typing in your administrator password” were the big vectors—and not very big at that.

As covered in which Mac sharing services are safe to turn on, the best advice is to not enable network services you don’t need.

Staff Writer
Follow:
Kristina is a staff writer at GeeksChalk, and is interested in all things Apple. This includes its best products such as the iPad, iPhone, Mac, AirPods, and Apple Watch. When she's not tinkering with the latest Apple gear, you’ll find her watching movies, taking pictures and exploring the great outdoors.
Leave a Comment