Rather than scanning for malware when a Mac is started or an app is launched, Apple has quietly added a feature whereby it scans whenever a Mac is idling.
Macs have famously been less prone to viruses than PCs, but all computers — and all computer users — are vulnerable to malware. Without explicitly announcing it, Apple has taken a further step to block and remove malware from the Mac.
According to Howard Oakley on his The Eclectic Light Company blog, Apple introduced what's called XProtect Remediator in March 2021, as part of its then latest macOS Monterey update.
It's an update to the long-standing XProtect system tool, which Oakley says "was mainly used to check apps... against a list of signatures of known malware."
Now XProtect Remediator "consists of executable code modules which both scan for and remediate detected malware."
Oakley says it is seemingly a replacement for Apple's previous Malware Removal Tool (MRT). And while searching Apple's support site for "malware" does surface references to the MRT, those references have been removed from the actual support documentation.
This XProtect Remediator is also not referenced in the support documentation, and XProtect is described as being for the removal of malware once detected. However, Apple does now say that XProtect also helps with the identification of malware.
"These scans should now be taking place on all Macs running macOS Catalina and later, with the current XProtect Remediator installed," says Oakley. "They're most likely to take place when your Mac is awake but doing little other than background tasks, such as routine backups, and receiving incoming email as it arrives."
Oakley describes this repeated system scanning as a "big step forward."
7 Comments
Endpoint protection services and software is an essential business that Apple is giving away to Microsoft and others.
it is a glaring gaping hole in the Apple service portfolio and security services is currently MS fastest growing segment and one of the reasons Azure was not ignored in favour of AWS.
A personal Microsoft 365 subscription includes Defender for MacOS.
Apple releasing obsolete scanning features is not impressive for a company that has trust and privacy as part of the value prop.
honestly - add another 5 dollars per month to AppleOne and include XDR like agents across the device family with iCloud as the management console. Ties well into the SMB push they are doing and MDM offering.
Users of Apple devices not being targeted or at lower risk is not true.
Can these scans be scheduled to not run when I'm doing performance testing or benchmarking?