Symantec says DevilRobber is the second most widespread Mac malware, behind RS Plug. The miner was first discovered by Intego researchers in October 2011 and was later spotted by F-Secure and Sophos a few days later. The malware was so widespread that Apple had to issue emergency updates to limit its impact. In recent years, Bitcoin mining has become a highly ineffective operation when performed on regular computers. It is plausible that a new version of the malware that mines for these latter cryptocurrencies instead of Bitcoin may be attributed to a spike in activity.
Source: https://www.bleepingcomputer.com/news/security/the-second-most-popular-mac-malware-is-a-cryptocurrency-miner/