WizardUpdate is a macOS malware family commonly classified as adware and frequently discussed alongside closely related macOS adware activity such as Pirrit. It has been distributed through deceptive installer packages, including script-only PKG installers that masquerade as legitimate software such as Adobe Flash Player. In these cases, the installer contains little or no meaningful embedded application payload and instead relies on installation scripts to profile the host, retrieve a second-stage archive from remote infrastructure at install time, execute the downloaded component, and remove temporary artifacts afterward. Observed scripts collect basic system information including the macOS version and a hardware-derived identifier, and may vary request parameters based on the victim environment.
WizardUpdate targets macOS systems and has been analyzed as part of broader efforts to cluster related macOS malware variants through shared code, obfuscation routines, and reusable logic. Reverse-engineering work has identified XOR-obfuscated strings in some samples, indicating at least moderate efforts at concealment and static-analysis resistance. The family is notable for using lightweight installer wrappers and server-delivered payloads, a design that can reduce static signatures in the initial package and allow operators to change delivered functionality on demand.
The malware has primarily been associated with unwanted software installation and adware-style monetization on macOS rather than destructive effects. Its observed behavior supports classification as a downloader or loader-style component within a larger adware ecosystem, with execution occurring through installer post-install scripts and follow-on payload retrieval. WizardUpdate is relevant to defenders monitoring macOS threats because it illustrates the continued use of deceptive software-themed lures, staged delivery, and minimal on-disk initial payloads to evade straightforward static detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS malware sample used in testing the multi-agent reverse-engineering pipeline; the content notes XOR-obfuscated strings were identified in the sample.
macOS malware referenced in detection content; the digest provides no functional details beyond being something defenders detect as an infection.
A macOS malware family used in the article as the primary example for creating and applying radare2 Zignatures and YARA hunting rules across variants.
A macOS adware family mentioned as also using script-only PKG installers where executable content is downloaded at install time rather than embedded in the package.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.