Silver Sparrow is a macOS malware downloader/dropper identified by Red Canary Intelligence that targets both Intel-based Macs and Apple Silicon systems, including Apple M1. It uses JavaScript during installation of PKG files such as updater.pkg and update.pkg to generate files and scripts on disk, and establishes persistence via LaunchAgents. Reported persistence artifacts include ~/Library/Launchagents/agent.plist and ~/Library/Launchagents/init_agent.plist, with a version 1 script at ~/Library/Application Support/agent_updater/agent.sh configured to execute every hour. Silver Sparrow checks in hourly and attempts to download an implant or payload from Amazon S3 infrastructure, including mobiletraits.s3.amazonaws[.]com, using files such as /tmp/version.json and /tmp/version.plist to determine execution flow; /tmp/agent.sh is used as an installation callback script, and /tmp/agent is identified as the location of a final version 1 payload if distributed. At the time of reporting, no malicious final payload had been observed to download, and the malware’s ultimate objective remained unknown. The initial distribution method was also unknown, though the authors suspected malicious search engine results may have directed victims to the PKG installers. Two known variants were described. Version 1 used updater.pkg (MD5: 30c9bc7d40454e501c358f77449071aa) and communicated with api.mobiletraits[.]com. Version 2 used update.pkg (MD5: fdd6fb2b1dfe07b0e57d4cbfef9c8149) and communicated with api.specialattributes[.]com. Both variants included extraneous Mach-O binaries that appeared to be placeholder content rather than functional malware components: version 1 included an Intel x86_64 binary named updater (MD5: c668003c9c5b1689ba47a431512b03cc) that displayed "Hello, World!", while version 2 included a universal x86_64/ARM64 binary named tasker (MD5: b370191228fef82635e39a137be470af) that displayed "You did it!". The bundled Mach-O binaries would only run if a victim intentionally launched them. The file ~/Library/._insu was described as an empty file used to signal the malware to delete itself, although the circumstances under which it appeared were unknown. SentinelOne assessed that Silver Sparrow may have been sold to third-party affiliates or pay-per-install partners, consistent with commodity adware or malware ecosystems. Malwarebytes reportedly observed nearly 30,000 affected hosts that had not yet received a next-stage payload at the time of publication. A revoked Apple Developer ID, Saotia Seay (5834W6MYX3), was associated with the version 1 bystander binary. Detection guidance in the source material emphasized suspicious use of PlistBuddy with LaunchAgents and RunAtLoad, sqlite3 with LSQuarantine, and curl with s3.amazonaws.com.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MacOS malicious software/adware contextually associated with suspicious SQLite3 LSQuarantine queries used to determine the original URL of downloaded packages.
Early Apple Silicon-native macOS malware (noted in 2021) distributed via a fake Flash update and capable of executing remote commands.
A macOS malware downloader/dropper that uses JavaScript during installation to generate files and scripts on disk, establishes persistence via LaunchAgent, supports both Intel and Apple M1 architectures, and attempts to download an implant from an S3 bucket every hour.
macOS malware/downloader delivered via PKG files that establishes persistence with LaunchAgents, downloads version information from S3, executes installation callback scripts, and can delete itself using a marker file. The final payload was not observed in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.