OSX/Tarmac is a macOS malware family observed in malvertising-driven fake Flash update campaigns. The provided content states that Shlayer has dropped OSX/Tarmac, and that in another observed infection chain an OSX/Bundlore loader delivered via malvertising downloaded OSX/Tarmac, which then installed a follow-on malware specimen named MapperState. Bundlore in that chain was reported as compiled for Apple Silicon (M1) and notarized by Apple. Tarmac is therefore positioned as an intermediate-stage macOS payload in multi-stage adware/malware delivery chains.
The content links OSX/Tarmac to broader fake update infrastructure used to distribute macOS malware, including campaigns that rapidly rotate domains, subdomains, Amazon S3 buckets, file sizes, and SHA-256 hashes to frustrate IOC-based detection. Shlayer and Bundlore are explicitly named as malware variants commonly spread through these fake Flash update landing pages, and Tarmac is described as being dropped by Shlayer in one case and by Bundlore in another.
The malware name “Tarmac” was derived by researchers from command strings found in a public flashcards app. The same reporting states that earlier OSX/Tarmac activity and later Hydromac/MapperState activity were linked through leaked command strings, and that an older Mughthesec sample reportedly contained OSX/Tarmac command strings labeled TRMC_XXX. Based on the supplied content, Tarmac is associated with the related macOS malware cluster involving Hydromac, MapperState, and Mughthesec.
High-confidence behavioral detail in the provided material is limited for Tarmac itself. The strongest directly stated behavior is that OSX/Tarmac downloaded or installed MapperState on a honeypot system. No standalone persistence mechanism, C2 domain, or file hash for Tarmac itself is provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named macOS malware referenced as being dropped by Shlayer.
macOS malware/adware family involved in a malvertising delivery chain. Mentioned as a prior-stage installer/dropper for MapperState/Hydromac components and noted for anti-analysis/slow-debugging string decryption tricks that later variants evolved to defeat published decryption tooling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.