AdLoad is a long-running macOS malware family primarily known for adware and browser-hijacking behavior, but it has also been documented as a bundleware loader and secondary-payload delivery mechanism. It targets macOS systems and attempts to hijack and redirect web browsing traffic, including through proxy-based traffic interception that enables search-result manipulation and advertisement injection. Multiple reports also associate AdLoad with harvesting system or user data and downloading or installing additional payloads, making some variants more capable than simple nuisance adware.
AdLoad has been active since at least 2017 and has repeatedly evolved to evade Apple’s native protections. Observed campaigns have used persistent installation patterns involving LaunchAgents, LaunchDaemons, and cron jobs, with payloads hidden under Application Support directories and naming conventions designed to blend in with legitimate macOS components. Some campaigns used multi-stage shell-script droppers, fake application installers, and notarized or developer-signed droppers to improve execution success on macOS. AdLoad has also been delivered by other macOS malware families, notably Shlayer and UpdateAgent, and has appeared in fake software or fake update distribution chains.
Operationally, AdLoad is associated with browser hijacking, advertisement injection, traffic redirection, persistence, and follow-on payload delivery. Some reporting further indicates that infected hosts may be incorporated into residential proxy or botnet-style infrastructure, and defenders have treated successful execution as potentially giving attackers broad control over the affected device. Microsoft has also linked suspicious AdLoad activity to possible abuse of Safari privacy-control bypass conditions around CVE-2024-44133, although direct exploitation of that specific vulnerability has not been conclusively confirmed.
AdLoad remains one of the most prevalent macOS malware families observed in enterprise and consumer environments, including education networks and broader business settings. Its continued prevalence, frequent repackaging, and overlap with other macOS malware delivery ecosystems make it a significant and persistent threat in the Apple platform malware landscape.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The droppers we have seen take the form of a lightly obfuscated Zsh script that decompresses a number of times... AdLoad binaries use a great deal of obfuscation, including custom string encryption
Interestingly, the droppers for this campaign share the same pattern as Bundlore/Shlayer droppers. They use a fake Player.app mounted in a DMG.
les attaquants peuvent accéder à des informations sensibles, notamment l'historique de navigation...
les attaquants peuvent accéder à des informations sensibles, notamment ... le microphone...
les attaquants peuvent accéder à des informations sensibles, notamment ... l'appareil photo...
notice the URL at 0x7226 . That could be interesting... We might do better if we try grabbing bytes of code right after that string has been loaded, for while the API string will certainly change, the code that consumes it perhaps might not.
The victim host conducts HTTP GET requests to a C2 domain... C2 activity begins via HTTP POST... An additional payload is downloaded from static.<domain>/d/<38 digit string>/<filename>... Detections Behavior MITRE ATT&CK Details AdLoad - ZIP file downloads from unknown domains T1071.001 HTTP
Adload leverages a Person-in-The-Middle (PiTM) attack by installing a web proxy to hijack search engine results and inject advertisements into webpages
320 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware associated with a residential proxy botnet targeting macOS and Windows users; the botnet has been observed delivering spam campaigns.
Adware/loader targeting macOS, capable of persistence and data collection.
macOS malware that hijacks and redirects web browsing traffic.
macOS adware family discussed in the context of using cron jobs (loaded in a certain way) as a persistence mechanism that can sidestep Apple Background Task Management (BTM) visibility.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.