Mughthesec is a macOS adware/malware family first publicly reported in 2017 and described as likely a variant of the SafeFinder/OperatorMac adware ecosystem. It masquerades as a Flash Player installer, including a signed installer disk image named Player.dmg with bundle identifier com.FlashPlayer and Apple Developer ID 'Quoc Thinh (9G2J3967H9)', allowing it to pass Gatekeeper at the time of analysis. The installer was reported as undetected by antivirus engines on VirusTotal when analyzed and used a basic anti-VM check based on MAC address inspection.
On execution, Mughthesec attempts to install additional adware and potentially unwanted applications including Advanced Mac Cleaner, Safe Finder, and Booking.com-related adware. It persists via a LaunchAgent at '~/Library/LaunchAgents/com.Mughthesec.plist', with RunAtLoad enabled and a 4-hour start interval, and drops its main unsigned payload at '~/Library/Application Support/com.Mughthesec/Mughthesec'. It hijacks the Safari homepage to 'http://default27061330-a.akamaihd.net/s?q=@@@&_pg=564D4420-C090-470B-9C13-6760B31264E7', installs the 'Any Search' browser extension, and redirects searches through affiliate infrastructure before ultimately using Yahoo Search with Safe Finder script injection.
Reported network infrastructure includes 'api.mughthesec.com' and 'mughthesec.com', with the latter resolving to 192.64.119.107 in the cited analysis. The installer was observed making outbound connections to domains including 'simplyeapps.com' and 'mughthesec.com'. Infection was assessed as likely occurring through fake popups or malicious advertisements requiring user interaction.
Later reporting linked Mughthesec to the broader Hydromac/OSX/Tarmac activity cluster. Confiant reported that a Hydromac Agent sample communicated with 'api.mughthesec.com', and that an original Mughthesec sample contained OSX/Tarmac command strings. Based on overlaps in command structure, payload relationships, and shared C2 infrastructure, Confiant concluded that Hydromac Agent, MapperState (assessed as a Hydromac Root Agent), and the 2017 Mughthesec sample were related and had been used in real malvertising campaigns. High-confidence identifiers mentioned in the source material include the original Mughthesec sample hash '9c4f74feff131fa93dd04175795f334649ee91ad7fce11dc661231254e1ebd84', the persistence path '~/Library/LaunchAgents/com.Mughthesec.plist', the payload path '~/Library/Application Support/com.Mughthesec/Mughthesec', and the domains 'api.mughthesec.com' and 'mughthesec.com'.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously documented macOS malware (2017) whose C2 infrastructure and command strings overlap with later Hydromac/Tarmac components, suggesting shared lineage or reuse of tooling/infrastructure across malvertising-driven campaigns.
macOS malware originally reported in 2017 that shares C2 infrastructure and command overlap with Hydromac and Tarmac, indicating relationship across these malware families.
Mughthesec is a macOS adware variant, likely related to the OperatorMac and SafeFinder adware families. It masquerades as a Flash Player installer, uses a signed installer to bypass Gatekeeper, and upon installation, hijacks browser settings (such as the homepage), installs browser extensions, and injects ads for financial gain. It also persists via a launch agent and is designed to evade detection by anti-virus and virtual machines.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.