Trojans accounted for about half of the malware activity in Jamf's 2025 Mac analysis, published in its 2026 Security 360 report. That share describes the mix of observed threats. It cannot tell an individual Mac owner their probability of infection. The useful lesson is to scrutinize software installation and script requests, and to include account recovery in your response to suspected malware.

Which Macs and dates Jamf studied

The methodology on page 3 describes an anonymous sample of more than 150,000 Macs, analyzed at the end of 2025 over the preceding 12 months. Malware research used devices in the United States; vulnerability research used global data. Jamf used aggregated logs without information identifying people or organizations.

The report does not give exact start and end dates, a separate US malware sample size, or whether multiple alerts from one file were counted more than once. The overall device count therefore cannot be used to calculate how many Macs had Trojans.

What the Trojan share means

Page 8 lists Trojans at 50.32%, infostealers at 33.52% and adware at 5.06% for 2025. Page 9 instead labels Trojans 50.40%; we use “about half” to reflect that small internal discrepancy. These are shares of Jamf's observed malware activity. To estimate how many Macs were infected, we would need both the number of infected devices and the total number of devices being studied.

That distinction matters when deciding what to do with a security headline. One Mac may produce several alerts, while another produces none. A blocked attempt can also have a different outcome from an infection that succeeds. Without the underlying counting rules, multiplying the report's percentage by its device sample would create an unsupported estimate of infected Macs.

A changing share also needs care: it can rise because one category grows, another shrinks, or classification changes. Assessing a change in absolute risk would require comparable counts and sampling across years. This report helps identify threats worth preparing for, while an individual's exposure still depends on their software, work and installation decisions.

How Trojans and infostealers affect a Mac

A Trojan disguises malicious software as something legitimate. An infostealer collects sensitive information. Those descriptions concern different aspects of an attack and can apply to the same malware. Jamf discusses stealers acquiring backdoor capabilities on page 12.

For the person using the Mac, the distinction helps organize a response. Data theft raises questions about which accounts, credentials or files were exposed. A backdoor raises an additional question: can someone return to the device? Removing the initial installer does not answer either question. Device cleanup and securing affected accounts need separate attention.

Our ClickFix and Script Editor explainer examines a concrete example reported in April 2026, after this dataset's observation period. It shows how a maintenance request can lead a user into running a script and identifies opportunities to stop before execution.

Practical steps for Mac owners

  • Check where software comes from. Navigate independently to the developer's site or an established distribution channel. Verify unexpected update requests through the installed app or your IT team.
  • Pause when a website asks you to run commands. A cleanup, verification or interview task that opens Terminal or Script Editor deserves independent verification before you execute anything.
  • Maintain software and recovery options. Keep macOS and applications updated, leave security warnings enabled, and maintain backups you can restore.
  • Prepare for account exposure. Use unique passwords and multifactor authentication, and know how to review sign-ins and revoke sessions for your important accounts.

If you suspect code has already run, stop using the Mac for sensitive accounts, disconnect it from networks and seek help from your security team or a trusted technician. Use a separate trusted device to change exposed passwords and revoke sessions. Preserve the original alert, download source and time of the incident to support investigation.

What to ask of a security tool

Look for evidence that matches the protection you need: which activity a tested build can detect, whether it alerts or blocks, what permissions it requires, and how it reports failures. Recognizing a known malicious file, noticing a suspicious process and blocking a covered network destination each address a different stage. A quiet dashboard alone cannot establish that an attempted attack was prevented.

PhantomProtect is our first planned release and remains in development. We’re testing how local file checks, activity analysis and threat information work together. Results from those tests will establish which attacks a released build can detect or block.

Sources