Quick Answer: How to Check for Malware on a Mac
To check for malware on a Mac, work through eight steps: open Activity Monitor for unusual processes, review Login Items for auto-starting apps you did not install, check Applications and Launchpad for unknown apps, verify XProtect and Gatekeeper are enabled in System Settings, run an on-demand scan with Malwarebytes for Mac (free), audit browser extensions and homepage settings, and check profiles in System Settings for configuration profiles you did not install. If symptoms persist after all eight steps, back up your data and do a clean macOS reinstall via Recovery Mode.
Can Macs Actually Get Malware?
Yes. Apple's built-in protections have improved dramatically, but Macs are not immune. The most common Mac-targeted malware families in 2025–2026 include:
- Atomic Stealer (AMOS) — a macOS infostealer sold on criminal forums and delivered through fake software updates and cracked apps.
- Shlayer — a macOS downloader that installs adware. It is delivered through poisoned search results on piracy sites.
- Pirrit — adware that hijacks browser settings and installs persistent launch agents.
- Generic browser hijackers — usually disguised as "PDF converters" or "video downloaders" installed via misleading Chrome pop-ups.
The "Macs don't get viruses" myth is exactly why Mac-targeted malware succeeds: it gets less user suspicion, fewer security tools, and slower patching than Windows equivalents.
Signs Your Mac May Have Malware
None of these symptoms alone confirms malware — but multiple together justify a thorough scan:
- The fan runs at high speed even when no heavy applications are open.
- Browser homepage or default search engine changes without your action.
- Unexpected pop-up windows or aggressive browser redirects.
- Apps appear in Launchpad or Applications that you did not install.
- The Mac runs unusually hot or the battery drains much faster than usual.
- You see unfamiliar login items at startup.
- Web searches get redirected through unfamiliar intermediates.
The 8-Step Mac Malware Check
Step 1: Open Activity Monitor
Open Activity Monitor from Applications → Utilities → Activity Monitor. Click the CPU tab and sort by CPU usage; click the Memory tab and sort by Memory. Look for processes with no recognizable app name — anything you cannot identify as belonging to a known Apple or third-party app.
Hover any unfamiliar process name to see its full path. Malicious processes often live in /Library/Application Support with random-looking folder names, or in /private/tmp/. If you find one, do not force-quit it immediately — note its name and location, then cross-reference on a security blog to confirm before removing.
Step 2: Audit Login Items
Open System Settings → General → Login Items (Ventura and later) or System Preferences → Users & Groups → Login Items (older macOS). Look for items you do not recognize. Anything listed there runs automatically every time you log in.
Step 3: Audit Applications and Launchpad
Open Applications and Launchpad. Look for apps you do not remember installing. If you find one, drag it to the Trash and empty the Trash. Note: drag-to-Trash often leaves behind support files — an on-demand scanner handles that.
Step 4: Verify XProtect Is Active
XProtect runs in the background by default and requires no configuration. To verify it has been updated, open System Settings → General → Software Update. The presence of recent security updates confirms XProtect's signature database is current. Apple pushes XProtect updates silently between full OS updates.
Step 5: Verify Gatekeeper Settings
Open System Settings → Privacy & Security → scroll down to Security. Confirm "Allow applications downloaded from" is set to App Store and identified developers. If you have ever clicked "Open Anyway" on an unsigned app, Gatekeeper was bypassed for that file — that file ran without Apple's signature check.
Step 6: Run an On-Demand Scanner
Download and install Malwarebytes for Mac (free version) or another reputable on-demand scanner. Run a full scan. The free version of Malwarebytes does not provide real-time protection but is excellent for periodic deep scans. For users who want always-on protection, the paid version adds real-time blocking.
Step 7: Audit Browser Extensions
Open Safari → Settings → Extensions, then repeat for Chrome → Extensions and Firefox → Add-ons. Remove any extensions you do not recognize or no longer use. Then check your homepage and default search engine in each browser's settings.
Step 8: Check Configuration Profiles
Open System Settings → General → Device Management (Ventura and later) or System Preferences → Profiles (older). Any profile listed there controls security, network, or VPN settings on your Mac. Remove any profile you did not install — some Mac malware installs profiles to persist VPN settings that route your traffic through attacker-controlled servers.
When to Do a Clean macOS Reinstall
If you have completed all eight steps and still see malware symptoms — or if you found a configuration profile you cannot explain — the next move is a clean reinstall. Back up your files (documents, photos, downloads) but do not restore apps from backups. Restore only files, not system configurations.
The clean-reinstall procedure:
- Use an external drive or Time Machine for file backup only.
- Restart into macOS Recovery (Intel: hold Command-R at boot; Apple Silicon: hold the power button).
- Erase the startup disk using Disk Utility.
- Reinstall the latest macOS version compatible with your Mac.
- Restore only files from backup — not apps or system preferences.
- Reinstall apps only from their official sites or the App Store.
- Restore browser bookmarks from your cloud sync, not from local backup.
Best Free and Paid Mac Security Tools
| Tool | Type | Cost | Best For |
|---|---|---|---|
| macOS XProtect + Gatekeeper | Built-in | Free | Always-on baseline protection |
| Malwarebytes for Mac | On-demand scanner | Free / $40/yr paid | Deep scans, periodic cleanup |
| CleanMyMac | Cleanup + scanner | ~$40 one-time | All-in-one maintenance |
| CrowdStrike Falcon | EDR | Enterprise pricing | Endpoint protection for businesses |
| Microsoft Defender for Endpoint | EDR | Enterprise pricing | Cross-platform protection |
| SentinelOne | EDR | Enterprise pricing | Autonomous AI-driven protection |
For broader defensive habits, see our 25 cybersecurity tips. To learn the analyst skills that detect what built-in tools miss, the TutorsBot Cyber Security Analyst Foundation course covers macOS forensics, malware triage, and endpoint hardening.






