OSX/Pirrit is an intrusive macOS adware family described as an OS X port of the Windows Pirrit adware. Analysis attributed in the provided content to Amit Serper shows it relies on social engineering rather than exploitation of macOS vulnerabilities to obtain elevated privileges, then establishes persistence and manipulates network traffic and browser settings for ad injection and tracking.
The malware was observed in app bundles including "sizzling.app" and "DemoUpdater," both containing unsigned x64 Mach-O binaries. Its installation flow uses shell scripts including rec_script.sh, update2.sh, and install_injector.sh. rec_script.sh reads a hidden user identifier from /Library/Preferences/com.common.plist, determines the active network interface, and configures pf packet-filter rules to redirect outbound HTTP traffic on port 80 to a local proxy at 127.0.0.1:9882, while exempting traffic generated by the hidden user to avoid proxy loops. install_injector.sh establishes persistence, creates a hidden local user with home directory under /var/<username>, stores details in /Library/Preferences/com.common.plist, sets Hide500Users in /Library/Preferences/com.apple.loginwindow to hide low-UID users from login/configuration screens, creates /etc/pf_proxy.conf, and installs a LaunchDaemon under /Library/LaunchDaemons named com.<randomCompanyName>.net-preferences.plist to run /etc/change_net_settings.sh at boot. The LaunchDaemon runs as root but executes the proxy as the hidden user via sudo -u. The hidden user password was hardcoded as "test," and the installer used a hardcoded UID of 401.
update2.sh derives a machine identifier from IOPlatformExpertDevice data, sends it to a server at 93a555685cc7443a8e1034efa1f18924.com, queries ipinfo.io/country for the victim country code, and conditionally changes Safari, Chrome, and Firefox homepage/search settings. Victims in the U.S., U.K., Spain, Australia, France, Germany, India, Italy, Netherlands, or New Zealand were directed to trovi.com; other victims were directed to search-quick.com. The script also reported successful installation to the same infrastructure and downloaded an archive, dit3.tgz, which contained an ad-injecting proxy, a clickjacker app bundle, and installation/configuration scripts including an uninstall script.
The malware shows cross-platform development artifacts: the "sizzling" binary contained the Windows registry path HKEY_LOCAL_MACHINE\SOFTWARE\Pirrit, supporting the assessment that this is a port of Pirrit. Referenced URLs included http://thecloudservices.net and http://thecloudservices.net/static/pd_files/ok.html, with the latter returning "OK" and assessed in the source as likely used for connectivity checks. Additional referenced URLs included shorte.st and google.com.
High-confidence indicators mentioned in the content include files and paths such as /Library/Preferences/com.common.plist, /etc/pf_proxy.conf, /etc/change_net_settings.sh, and /Library/<companyname>/; network indicators including *.93a555685cc7443a8e1034efa1f18924.com, *.trkitok.com, *.aa625d84f1587749c1ab011d6f269f7d64.com, *.2ff328dcee054f2f9a9a5d7e966e3ec0.com, *.aae219721390264a73aa60a5e6ab6ccc4e.com, search-quick.com, and trovi.com; and MD5 hashes 85846678ad4dbff608f2e51bb0589a16 for the installer and 70772fccaec011be535d1f41212f755f for the proxy.
The provided content does not associate OSX/Pirrit with a named nation-state or criminal threat actor. It characterizes the malware primarily as adware, but notes that its persistence and traffic-control mechanisms could be repurposed for more serious post-compromise activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cross-platform adware ported to macOS that establishes persistence via LaunchDaemon, creates a hidden local user (UID 401) with a hardcoded password, configures pf rules to transparently redirect HTTP (port 80) traffic through a local proxy (127.0.0.1:9882) for ad injection/clickjacking, and hijacks browser homepage/search settings (e.g., Trovi.com or Search-quick.com) based on geolocation.
OSX/Pirrit is intrusive adware for macOS, using various persistence and evasion techniques.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.