UpdateAgent is a macOS trojan/loader first observed in September 2020. It began as a basic information-stealer focused on reconnaissance, collecting system information from infected Macs and sending it to command-and-control infrastructure, and later evolved into a more capable malware family able to fetch and execute secondary payloads. Reported reconnaissance includes basic host details, system_profile/SPHardwaretype data, and use of commands such as system_profiler SPHardwareDataType. In the 3CX supply-chain incident, the macOS first stage dropped UpdateAgent as a second-stage payload; that UpdateAgent variant self-deleted after execution and collected 3CX account name and provisioning URL information before exfiltration.
UpdateAgent has been distributed via trojanized ZIP and PKG installers impersonating legitimate software, including HelperModule.zip and WebVideoPlayer.pkg, and has also been assessed as likely spread through drive-by downloads or advertisement pop-ups masquerading as legitimate applications. In the 3CX compromise, a trojanized macOS 3CX Desktop App delivered UpdateAgent as the second stage. The malware has been observed installing under paths such as /Library/Application Support/Helper/HelperModule and /Library/Application Support/WebVideoPlayer/WebVideoPlayerAgent.
Across multiple iterations, UpdateAgent added secondary payload delivery, persistence, privilege abuse, and defense evasion. It fetched additional payloads from public cloud infrastructure, initially as DMG files and later as ZIP files, including from Amazon S3 and CloudFront. It bypassed Gatekeeper by removing quarantine attributes with xattr, checked Quarantine Events data via sqlite3/LSQuarantineDataURLString, created persistence via PLIST files in LaunchAgent folders, and later shifted to LaunchDaemon persistence requiring administrative privileges and enabling root-level execution. Microsoft also reported that later variants leveraged existing user profiles for sudo-requiring commands and modified the sudoers list to suppress credential prompts. Variants used curl for C2 communications and payload retrieval, and deleted payloads, temporary folders, PLIST files, and other artifacts to reduce forensic evidence.
UpdateAgent has been observed delivering Adload adware as a secondary payload. Microsoft reported this behavior in the October 2021 campaign, and later reporting in education-sector networks in 2023 again associated UpdateAgent activity with AdLoad infections, although the exact infection sequence was not confirmed in that dataset. Adload was described as capable of proxy-based traffic hijacking, ad injection, additional payload delivery, and system information harvesting.
The malware has been discussed in connection with several campaigns and reporting streams. Microsoft extensively tracked its evolution through October 2021. SentinelLabs identified UpdateAgent as the macOS second-stage payload in the 3CX supply-chain attack. ESET referred to the 3CX macOS payload as UpdateAgent and assessed the broader 3CX operation with high confidence as conducted by Lazarus, though attribution of UpdateAgent itself should be understood in the context of that campaign. IronNet also observed UpdateAgent among prevalent macOS malware affecting education environments in August 2023, likely from already-infected BYOD devices.
Known indicators and artifacts directly mentioned in the content include installation paths under /Library/Application Support/Helper/HelperModule and /Library/Application Support/WebVideoPlayer/WebVideoPlayerAgent; use of HelperModule.zip and WebVideoPlayer.pkg; abuse of Amazon S3 and CloudFront-hosted payload URLs; command usage including system_profiler SPHardwareDataType, curl, xattr, sqlite3, and PlistBuddy; and in the 3CX macOS chain, a hidden identifier file named .main_storage dropped alongside UpdateAgent.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
UpdateAgent lures its victims by impersonating legitimate software and can leverage Mac device functionalities to its benefit.
UpdateAgent removes evidence by deleting the secondary payload, temporary folders, PLIST files, and all other downloaded artifacts.
Once installed, UpdateAgent starts to collect system information that is then sent to its command-and-control (C2) server.
Once the compromised device connects to the C2 server, the trojan uses a curl request to send this data to the C2 server.
The victim host conducts HTTP GET requests to a C2 domain... C2 activity begins via HTTP POST... An additional payload is downloaded from static.<domain>/d/<38 digit string>/<filename>... Detections Behavior MITRE ATT&CK Details AdLoad - ZIP file downloads from unknown domains T1071.001 HTTP
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MacOS trojan observed using encrypted communications over TCP port 1027 and stealing basic system information. The content also notes Microsoft reported AdLoad as a secondary payload delivered by UpdateAgent.
Second-stage macOS payload dropped by the trojanized 3CX Desktop App. It self-deletes after execution and primarily performs host/installation reconnaissance (e.g., 3CX account name and provisioning URL) and exfiltrates the data to a hardcoded attacker-controlled server.
macOS trojan/infostealer that performs host reconnaissance and exfiltrates system information to a C2, while evolving into a loader capable of fetching and executing secondary payloads (.dmg/.zip) from public cloud (S3/CloudFront). It implements persistence via LaunchAgent/LaunchDaemon PLISTs, bypasses Gatekeeper by removing quarantine attributes (xattr) and checking quarantine DB entries (sqlite), and attempts privilege-related abuse (sudo/sudoers modifications) while cleaning up artifacts to evade detection.
A macOS trojan first seen in September 2020 that evolved from basic system reconnaissance and information theft into a more sophisticated loader with persistence, Gatekeeper bypass, quarantine attribute removal, sudo/sudoers abuse, PLIST-based persistence, evidence deletion, and delivery of secondary payloads from AWS infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.