Shlayer (also referred to as OSX.Shlayer) is a macOS adware dropper/installer primarily distributed through social engineering, most notably as fake Adobe Flash Player installers. Reported delivery lures include fake Flash update pages and a malicious site impersonating the Homebrew project (homebrew.sh). The malware has been observed executing shell commands via bash and using OpenSSL to decrypt and execute payloads. Its primary function is to install additional macOS adware, with reported payloads including Bundlore and MacOffers. Shlayer has also been notable for obtaining Apple notarization, allowing malicious signed payloads to bypass macOS security controls and run on Big Sur and earlier versions. Apple revoked some associated developer certificates after disclosure, but subsequent notarized payloads signed with different developer IDs were reported. Based on the provided content, Shlayer is associated with financially motivated adware activity targeting macOS users and relies heavily on fake installers and user interaction for infection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
OSX.Shlayer is a highly prevalent macOS malware family that masquerades as legitimate software (often Adobe Flash Player installers) to trick users into installing it. Its primary function is to download and persistently install various macOS adware, most notably Bundlore. It is known for its ability to bypass macOS security mechanisms, including Apple's notarization process, and is considered the most common macOS malware.
Dropper that masquerades as a Flash installer, downloads and installs various macOS adware such as MacOffers and Bundlore.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.