Shlayer is a prevalent macOS malware family best known for posing as an Adobe Flash Player update and relying on user execution of a mounted disk image to start infection. It has been widely distributed through malicious advertising and deceptive landing pages that redirect victims to fake update installers. Typical infection chains involve a malicious DMG containing a hidden script or application that the user launches manually.
Shlayer functions primarily as a downloader and staging mechanism for additional payloads. It can decode and decrypt downloaded content using Base64 and AES, and some variants have used native tools such as OpenSSL during payload handling. Reported variants have used multiple code-signed application stages and encrypted scripts to retrieve and execute second-stage malware on macOS. Shlayer has also been observed abusing gaps in macOS quarantine enforcement by downloading follow-on payloads in ways that avoid normal Gatekeeper and XProtect checks.
The malware employs multiple defense-evasion techniques. It masquerades as legitimate software updates, especially Flash Player, executes components from hidden directories within mounted disk images, and can disable macOS Gatekeeper through native system tooling. Its role in campaigns has often been to deliver additional macOS malware, including more feature-rich second-stage implants.
Shlayer targets macOS systems and has been one of the most common malware families observed on that platform since its discovery in 2018. It is associated with malvertising-driven distribution and fake software update lures rather than exploitation of a specific vulnerability. High-confidence reporting supports its use as a downloader in multi-stage macOS intrusion chains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
OSX/Shlayer has been a very common macOS malware this year, most of the time delivered through bad ads... Today’s OSX/Shlayer is still delivered through bad ads... Confiant detected and analyzed OSX/Shlayer since January 2019, originating from a malvertiser that Confiant have dubbed VeryMal.
In the case of Safari, part of the process involves an AppleScript that enables an accessibility setting that provides keyboard access to all controls—and then uses that access to click the “Allow” button in the window Safari displays when the user tries to install a Safari extension.
This shell script, which kicks off the entire installation process, consists of around 300 lines of code... The script next determines the version of the system and performs one set of actions on macOS 10.11 and higher, and another on older systems.
In several places, the installation process will attempt to modify the TCC.db database... This adware attempts to give itself and a wide swath of other processes one of the most powerful capabilities: Accessibility access.
Several browser extensions are installed for either Safari or Chrome or both... this adware uses a number of shady tricks... to get these extensions installed without the user needing to approve them or even being aware they've been installed.
Launch agents and daemons provide one of the most common ways for processes to stay persistently running on macOS. Crossrider adware installs multiple agents or daemons, depending on which files are being installed.
Launch agents and daemons provide one of the most common ways for processes to stay persistently running on macOS. Crossrider adware installs multiple agents or daemons, depending on which files are being installed.
executed through user installation of an executable disguised as a flash installer... malware look like Flash Player, Office, or PDF documents... compromised installation files for legitimate software.
Bad Rabbit has masqueraded as a Flash Player installer through the executable file install_flash_player.exe.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
The problem is not all of macOS applications are quarantine aware.. and curl is a one good example... The extended quarantine attribute will not be set for this malware, so none of GateKeeper nor XProtect will kick in... This would be a total bypass of macOS built-in malware security features.
84 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A common macOS malware family delivered via malvertising and fake Adobe Flash Player updates. In this campaign it acts as a staged loader that abuses signed apps and scripts to download and execute OSX/Tarmac, while bypassing macOS quarantine-based protections by using curl.
Software changes: ... OSX/Shlayer
Mac trojan that Base64-decodes and AES-decrypts downloaded payloads, including via openssl.
Malware that relies on users mounting and executing a malicious DMG file.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.