Fake File Opener is macOS adware reported by Malwarebytes and analyzed by Thomas Reed. It is installed via a fake security alert originating from AdvancedMacCleaner.com and presents itself as "Mac File Opener.app" signed to pass default Gatekeeper checks. Its persistence mechanism is unusual for macOS adware: instead of relying on a LaunchAgent, it registers itself in its Info.plist as the default document handler for many file types, causing the application to launch whenever a user opens files of those types. When executed, it displays a popup containing a "Search Web" button that opens a macfileopener.com URL intended to drive additional adware installations. The provided content characterizes it as adware and notes this document-handler registration as its distinctive persistence behavior.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
"Finally the malware authors re-signed the (now) infected application so that GateKeeper ... would not prevent the malware from executing"; Keydnap: "(re)signed, with another stolen or fraudulently obtained Apple developer ID"; Fake File Opener: "was signed, Gatekeeper ... would allow it to execute"
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Adware installed via fake security popups; achieves a novel pseudo-persistence by registering itself as the default document handler for many file types, then drives users to adware sites/popups to install additional unwanted software.
Adware installed via fake security popups; achieves a novel pseudo-persistence by registering itself as the default document handler for many file types, then drives users to adware sites/popups to install additional unwanted software.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.