Shlayer is a widely distributed macOS malware family best known as a first-stage downloader and dropper that has been one of the most prevalent threats affecting Mac users since at least 2018. It is commonly disguised as an Adobe Flash Player update or other benign application and is heavily associated with malvertising and deceptive landing pages. Distribution has also relied on malicious or hijacked websites, affiliate-driven traffic redirection, fake software update prompts, and links placed on high-traffic legitimate sites to lure users into downloading installer packages, often in DMG format.
Its primary role is to execute an initial infection stage, collect basic host information, retrieve additional payloads, and launch them on the victim system. Shlayer has historically delivered adware families including Bundlore, Cimpli, AdLoad, Pirrit, Bnodlero, and Geonei, making it a major enabler of ad fraud and intrusive browser manipulation on macOS. Delivered payloads have been observed installing malicious browser extensions, intercepting or redirecting searches, inspecting web traffic, and presenting deceptive password prompts. Public reporting has also described variants that use shell scripts, Python, Zsh, and Mach-O components, with extensive use of native macOS utilities for staging, decryption, unpacking, and execution.
The malware family is notable for repeated adaptation to macOS security controls. Reported variants have used obfuscation, encrypted configuration data, temporary staging directories, quarantine-aware logic, and techniques intended to bypass or weaken Gatekeeper, notarization, file quarantine, and related protections. One documented evolution embedded AES-encrypted configuration data inside modified DMG structures without breaking normal mounting behavior. Other variants queried quarantine metadata, enumerated mounted images, or used cloud-hosted infrastructure and rapidly changing delivery paths to complicate detection and tracking. Shlayer has also been reported as abusing a macOS Gatekeeper bypass vulnerability and, at one point, malicious samples were notarized by Apple, allowing execution under default Gatekeeper settings.
Shlayer primarily targets macOS users and has been observed broadly in consumer environments as well as in sectors such as education. Although often discussed alongside adware, it is more accurately characterized as malware because it relies on masquerading, social engineering, staged payload delivery, and defense-evasion techniques to establish a foothold and execute secondary code. Its operators and distributors have been linked to large-scale malvertising ecosystems, including campaigns such as VeryMal and traffic sources associated with Yosec. Shlayer has also appeared in reporting on commodity malware used in broader intrusion activity, underscoring its utility as an initial access and payload delivery mechanism rather than a purely nuisance threat.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2021-30657 April 26 macOS Gatekeeper bypass abused by Shlayer malware
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Feb 2020 Campaign: 모래종이(Sandpaper) ... Observed commodity malware: Shlayer and Mirai bot.
The bad actor is known for running large scale fake Flash update campaigns that are hosted on .icu domains by way of display ad auto-redirects: VeryMal Fake Flash Update — Shlayer Trojan
Yosec — ... They are a major source of distribution for the notorious Shlayer trojan: OSX/Shlayer ...
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Note the decrypted string that corresponds to commands, OSX/Shlayer.F executes them via popen() function.
The malicious shell scripts used by Shlayer and Bundlore are usually malvertising-focused adware bundlers using shell scripts in the kill chain to download and install an adware payload.
The most recent Shlayer variant is Trojan-Downloader.OSX.Shlayer.e... written in Python rather than Bash... the seemingly standard installer turns out to be a Python script.
After unpacking the archive, the main Python script uses the chmod tool to assign the file 84cd5bba3870 permission to run in the system. After that, the trojan runs the downloaded and unpacked application package using the built-in open tool.
The bash script in these variants decrypt the next stage encrypted blobs containing the next stage bash scripts using openssl with base64, Advanced Encryption Standard (AES), CBC (Cipher Block Chaining) to thwart security scanners.
Shlayer is a trojan downloader, which spreads via fake applications that hide its malicious code... Cimpli masquerades as a useful Mac utility (i.e., “Any Search”).
After that, the Trojan runs the downloaded and unpacked application package using the built-in open tool, and deletes the downloaded archive and its unpacked contents.
encrypted string ref in function 0x100020a50 decoded to : defaults read /System/Library/CoreServices/SystemVersion.plist ProductVersion
Next, the main script generates a unique user and system ID, and also collects information about the version of macOS in use.
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as commodity macOS malware whose techniques were echoed or improved upon by the APT32 backdoor delivery chain.
macOS malware family cited as using LaunchAgents/LaunchDaemons for persistence.
macOS malware family cited as using curl to download secondary payloads and bypass Gatekeeper by avoiding quarantine attributes.
A Mac-focused trojan delivered via fake Flash update malvertising campaigns and auto-redirects. In this report, the campaign uses Firebase/Firestore-hosted payloads, fingerprinting, obfuscation, and redirects to deliver the Shlayer binary.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.