Hydromac is a macOS malware/adware family documented in 2021 and linked to real-world malvertising-driven infection chains. Confiant observed related activity on major U.S. publisher websites, where an ARM-compatible, Apple-notarized OSX/Bundlore loader delivered OSX/Tarmac, which then installed a specimen named MapperState. Researchers assessed MapperState to be a Hydromac Root Agent based on decrypted command naming such as HM_RA_Init_1 and other HM_RA_* overlaps with Hydromac command data recovered from a public flashcards app. Hydromac components identified in the reporting include a Root Agent, an Agent, and an Agent Plugin.
Observed Hydromac behavior includes persistence via a LaunchDaemon plist named com.MapperState.system.plist, configured to run MapperState.system at load. The malware used heavy string and argument obfuscation, including repeated decryption blocks, to hinder reverse engineering. Decrypted strings indicated downloader functionality: it could fetch and execute additional programs and check for installed antivirus products. In the analyzed case, the C2 returned empty content, so the follow-on payload was not identified.
Hydromac is associated in the reporting with OSX/Tarmac and the older macOS malware Mughthesec. A hunted Hydromac Agent sample with SHA-256 7f7c7e1b181142592b2f8b7c823a969fb79160c9a5920abd718364eae98d1496 communicated with api[.]mughthesec.com, infrastructure previously tied to Mughthesec. The MapperState/Hydromac Root Agent sample had SHA-256 919d049d5490adaaed70169ddd0537bfa2018a572e93b19801cf245f7fd28408 and communicated with mapperstate[.]com. High-confidence indicators and artifacts mentioned in the content include mapperstate[.]com, api[.]mughthesec.com, com.MapperState.system.plist, MapperState.system, and HM_RA_* command strings. The reporting concludes that Hydromac, MapperState, OSX/Tarmac, and Mughthesec are related malware used in malvertising campaigns targeting macOS, including Apple Silicon systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A new macOS adware specimen, leaked from a flashcards app, focused on ad injection.
macOS adware family with multiple components (Root Agent, Agent, and Agent Plugin per leaked flashcards). The Root Agent (observed as MapperState) establishes persistence via LaunchDaemons, decrypts/obfuscates strings heavily, checks for installed AV, and appears to act as a downloader capable of fetching and executing additional binaries from C2.
macOS malware family with multiple components including Root Agent, Agent, and Agent Plugin. The Root Agent handles initial commands related to downloading and executing binaries, and the family shares infrastructure and command overlap with Mughthesec and Tarmac.
Hydromac is a macOS adware specimen, analyzed for its infection and persistence mechanisms.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.