@atpfm

On the topic of screen recording permissions and its abuse (or lack thereof), Infostealer malware is one of the more prominent types of malware we see on macOS. Here’s a recent example that has the ability to take screenshots:

https://www.kandji.io/blog/malware-cuckoo-infostealer-spyware

These infostealers of course typically prey on unsuspecting users and, being on macOS, tend to get much less coverage than their Windows counterparts. But there are plenty of interesting delivery methods that have made these more prominent in recent years, such as SEO poisoning, malicious advertisements, or masquerading as legitimate sys admin tooling (the most scary vector in my opinion).

Malware: Cuckoo Behaves Like Cross Between Infostealer and Spyware

Kandji's threat research team has discovered a piece of malware that combines aspects of an infostealer and spyware. Here's how it works.