How to scan my Mac for Malware

I know that I fell for the Punchbowl Invitation phishing scam and clicked where I shouldn't have.


How can I scan my Macbook Pro for Malware?


Currently running macOS Sequoia 15.5, but was at 15.1 (I believe) when it occurred last week.


MacBook Pro 13″, macOS 15.5

Posted on May 21, 2025 6:42 AM

Reply
Question marked as Top-ranking reply

Posted on May 21, 2025 8:14 AM

Phishing compromises are unrelated to the contents or security of your Mac. Service credentials, payment card details, Apple Account password, those can be requested by and exposed to the phishing. I’d expect a Punchbowl phishing to ask for Punchbowl credentials.


Not unless the scam had you download apps to your Mac, or provide remote access into your Mac. If you did do that, then the path is restoring a pre-breach backup, and changing all passwords.


One thing that can be an immense problem here is password re-use. If you;re using the same email and password with multiple services, getting that password phished in one place can (does) lead to breaches in other places where that password was re-used. This is where using unique passwords, and using passkeys where the services support those, are helpful. If you re-used that phished password, get to work changing it everywhere it was used.


On the local Mac, malware scans won’t detect compromised credentials* or enabling remote access or various sorts of backdoors, because that is something that the user specifically requested.


macOS has in-built malware scanning, and that detects and remediates most common problems.




*Apple has a separate tool that reports password compromises, integrated with the Passwords app. Other add-on security tools can have similar checks. if you want to see some of where your email and password may or has been compromised, visit https://haveibeenpwned.com and enter your email address.

16 replies
Question marked as Top-ranking reply

May 21, 2025 8:14 AM in response to Nickbo851

Phishing compromises are unrelated to the contents or security of your Mac. Service credentials, payment card details, Apple Account password, those can be requested by and exposed to the phishing. I’d expect a Punchbowl phishing to ask for Punchbowl credentials.


Not unless the scam had you download apps to your Mac, or provide remote access into your Mac. If you did do that, then the path is restoring a pre-breach backup, and changing all passwords.


One thing that can be an immense problem here is password re-use. If you;re using the same email and password with multiple services, getting that password phished in one place can (does) lead to breaches in other places where that password was re-used. This is where using unique passwords, and using passkeys where the services support those, are helpful. If you re-used that phished password, get to work changing it everywhere it was used.


On the local Mac, malware scans won’t detect compromised credentials* or enabling remote access or various sorts of backdoors, because that is something that the user specifically requested.


macOS has in-built malware scanning, and that detects and remediates most common problems.




*Apple has a separate tool that reports password compromises, integrated with the Passwords app. Other add-on security tools can have similar checks. if you want to see some of where your email and password may or has been compromised, visit https://haveibeenpwned.com and enter your email address.

May 21, 2025 8:53 AM in response to Ronasara

Ronasara wrote:

I recently found that EtreChek had been changed to pay only.

Still appears to be free:


How to use EtreCheckPro for free:

  1. First, download EtreCheckPro and run it
  2. Pick a problem, enter a description, and start your report
  3. Wait about 3 minutes for EtreCheck to run...
  4. Look for Major problems
  5. Look for Minor problems
  6. Fix security settings - find and remove malware
  7. If you need more help, share your report on the internet
  8. Find and fix Storage problems

May 21, 2025 1:58 PM in response to Ronasara

Ronasara wrote:

I've use EtreCheck for years, off and on. When I decided to download and install a current version,There was no way to do so unless I paid for it. Maybe I missed something or perhaps they have since changed their decision. As to the others I mentioned, I simply did an internet search and if I remember correctly, one or two names came up. I did not save them, however.

Make sure that you are ONLY downloading it from the EtreCheck website. I wonder if you went to some other website that is trying to capitalize on etresoft's hard work.


The link Owl-53 provided takes you to a page that says, "How to Use EtreCheck Pro for Free" and has a big "Free Download" button.

May 21, 2025 2:53 PM in response to Ronasara

Ronasara wrote:

I've use EtreCheck for years, off and on. When I decided to download and install a current version,There was no way to do so unless I paid for it. Maybe I missed something or perhaps they have since changed their decision. As to the others I mentioned, I simply did an internet search and if I remember correctly, one or two names came up.


Be advised that in the past I found alleged sources for EtreCheck that bundled malware with it. At the time I advised Mr Etresoft of that fact. It was particularly odious in that the version it hosted was outdated. I don't know what happened to those websites; I did not frequent them enough to remember what they were, but I know taking down such sites can be a monumental legal effort that is often not worth the time and expense. Only Apple has that kind of money. Forget about small developers.


Nothing is simpler than bundling malware with legitimate free software, and hosting it as an installable package. It's a short few steps from there to making such malware float to the top of a Google search. SEO companies are tripping over themselves to make that happen for anyone willing to pay them for the service. It doesn't take much imagination to realize the number of bad actors wanting a piece of that action.


There are plenty of links to EtreCheck on this site. No need to use a search engine.



Effective Defenses has long advised against obtaining software from unauthorized sources:


  • If you need to install software that isn't available from the Mac App Store, obtain it only from legitimate sources authorized by the software's developer.


... as well as a general recommendation against using popular search engines for that purpose, but what I really prefer to say is to avoid the most popular search engine. The overwhelming majority of its millions of results found in 0.23 seconds will be scams of one form or another, and the most popular results will be those that accrue the most revenue for that search engine provider.


You don't have to play that game.

May 21, 2025 2:04 PM in response to IdrisSeabright

IdrisSeabright wrote:


Ronasara wrote:

I've use EtreCheck for years, off and on. When I decided to download and install a current version,There was no way to do so unless I paid for it. Maybe I missed something or perhaps they have since changed their decision. As to the others I mentioned, I simply did an internet search and if I remember correctly, one or two names came up. I did not save them, however.
Make sure that you are ONLY downloading it from the EtreCheck website. I wonder if you went to some other website that is trying to capitalize on etresoft's hard work.

The link Owl-53 provided takes you to a page that says, "How to Use EtreCheck Pro for Free" and has a big "Free Download" button.

Thx. 👍

May 21, 2025 6:20 PM in response to John Galt

John Galt wrote:

Be advised that in the past I found alleged sources for EtreCheck that bundled malware with it. At the time I advised Mr Etresoft of that fact. It was particularly odious in that the version it hosted was outdated.

I don't know if the pirate versions of EtreCheck ever contained malware. I honestly never did that much research on it. As far as I know, they were simply hacking EtreCheck's in-app purchase so it would provide the Power User features without payment - or at least, without payment to me. I think some of them actually did charge money for the pirate version.


The fascinating part was the level of technical sophistication that was employed to hack my little app. At least I learned a lot about anti-piracy strategies.


Another curious aspect was that only EtreCheckPro got hacked, not the Mac App Store version. Today, there are lots of people talking about a future "golden age" of Apple software when US and EU governments finally tear down Apple's garden wall. The idea is that it will be a golden age of piracy for most apps.


I don't know what happened to those websites

One changed from "twitter.com" to "x.com". This isn't "dark web" stuff. It's big business - well "organized", if you get my meaning. Google and others work hard to keep the vast amount of open criminal activity on the internet hidden from casual web searches. But if you know the right keywords, you'll be amazed at what's available.


Effective Defenses has long advised against obtaining software from unauthorized sources:

• If you need to install software that isn't available from the Mac App Store, obtain it only from legitimate sources authorized by the software's developer.

... as well as a general recommendation against using popular search engines for that purpose, but what I really prefer to say is to avoid the most popular search engine. The overwhelming majority of its millions of results found in 0.23 seconds will be scams of one form or another, and the most popular results will be those that accrue the most revenue for that search engine provider.

You don't have to play that game.

Don't play the AI game either. AI chatbots are easier to hack than search engines so that they'll provide malicious information.

May 21, 2025 8:13 AM in response to Ronasara

Ronasara wrote:

I recently found that EtreChek had been changed to pay only. However, I also found that there are now free apps out there which apparently do he same thing.

It has been a while since I purchased a Licence for this software


Maybe things have changed ?


Though the Implications from the Main Page of this software seem to indicate


" Purchase the Power User package to: " etc


May 21, 2025 1:45 PM in response to etresoft

I've use EtreCheck for years, off and on. When I decided to download and install a current version,There was no way to do so unless I paid for it. Maybe I missed something or perhaps they have since changed their decision. As to the others I mentioned, I simply did an internet search and if I remember correctly, one or two names came up. I did not save them, however.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

How to scan my Mac for Malware

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.