🇵🇹 Daily Portugal news for expats & investors — FREE Subscribe

Mac Threat Detections in Portugal Rose 65% in Six Months, Nearly Twice the Global Pace

Detections of threats aimed at macOS rose 65% in Portugal in the first half of 2026, nearly double the global rate, according to security firm ESET. A credential-stealing trojan led the pack, phishing accounted for 40% of blocked threats, and only 4.3% of Portuguese small firms apply the full set of

Mac Threat Detections in Portugal Rose 65% in Six Months, Nearly Twice the Global Pace

The long-held belief that Apple computers are broadly safe from malware is looking shakier in Portugal. Detections of threats aimed at macOS systems rose 65% in the country over the first half of 2026, according to new national figures shared by the security firm ESET — nearly double the 38% increase the company recorded worldwide over the same period. The data, drawn from ESET's H1 2026 global threat report covering December 2025 to May 2026, suggests Portuguese Mac users are being targeted more aggressively than the global average.

The most common threat on Portuguese Macs was a credential-stealing trojan known as OSX/PSW.Agent, which accounted for 31.6% of all detections on the platform. Behind it came potentially unsafe tools such as OSX/Keygen (17.3%) and unwanted "cleaner" programs like MacBooster and MacKeeper, each responsible for 8.2% of cases. Ricardo Neves of ESET Portugal was careful to frame what the numbers mean: "These figures show that the growth results from a combination of programs designed to steal information and potentially unwanted or unsafe software," he said, adding that these are detections — threats intercepted — "not necessarily successful infections." His broader point was blunter: macOS "is increasingly included in attackers' campaigns and should not be regarded as an ecosystem immune to threats."

Email fraud remains the dominant attack vector nationally. Phishing now makes up close to four in every ten threats blocked in Portugal — roughly 40% of the total. Corporate systems are under sustained pressure too: attempted exploits against SQL database services climbed 15.5% over the period, attacks on the SMB file-sharing protocol grew 13.6%, and attempts against RDP remote-desktop connections rose 11.6%.

ESET's global report flags where the next wave may be heading. It documents the emergence of PromptSpy, described as the first known Android malware to weave real-time generative artificial intelligence into its own execution, querying a remote AI model through an external connection to interpret what was on the screen and decide what to do next. Only a single detection was recorded, in Ukraine, tied to a fake JPMorgan Argentina app — but Neves called it an early sign of "a new generation of more flexible malware" that could adapt its behaviour to each device. The report also tracked the rise of "quishing," phishing carried out through QR codes, which reached an average of 100,000 detections a month globally at the start of 2026. A QR code, Neves warned, "hides the destination address" and often shifts the victim from a monitored work computer to a personal phone with weaker protections.

Where Portugal is most exposed, though, is in the basics. Neves cited figures from the Centro Nacional de Cibersegurança (National Cybersecurity Centre, or CNCS) showing that while 95.1% of the country's small firms adopt at least one security measure, only 4.3% apply the full set of recommended controls. Just 36% use multi-factor authentication and only 37% carry out active risk management. His advice for the second half of the year was to close that gap: for households and small businesses, that means moving beyond basic antivirus to patch management, email security and multi-factor authentication — and, for individuals, treating an unexpected QR code or email link with the same suspicion regardless of whether it lands on a Mac, a Windows PC or a phone.