Genieo is macOS adware identified in the provided content as a browser hijacker. It is also referred to as DOLITTLE in one mention context. The content associates Genieo with macOS malware activity observed in education-sector environments in early to mid-August 2023, where IronNet assessed infections were likely introduced by already-infected personal devices brought onto school networks, particularly in higher education BYOD settings. In a separate suspicious macOS campaign observed in those environments, a later ZIP archive contained a payload named CompanyUpdate that VirusTotal identified as Genieo adware. That campaign involved encrypted C2 communications, additional payload delivery via ZIP archives, HTTP POST requests to /reader-update with a unique device_id parameter, and encrypted POST requests to /squirrel-log containing _iv= and _payload= parameters. Another mention context states that ReaderUpdate acted as a loader to serve Genieo adware. The content also tags Genieo in relation to macOS mdls utility activity mapped to Defense Evasion and Discovery, but does not provide direct evidence that this behavior is unique to Genieo. High-confidence indicators and artifacts directly mentioned in connection with the broader observed campaign include the CompanyUpdate payload name, the /reader-update and /squirrel-log HTTP POST paths, and the parameters device_id, _iv, and _payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
mdls list file metadata across standard metadata (creation date, size), extended attribute (quarantine), and Spotlight APIs (Finder flags).
The victim host conducts HTTP GET requests to a C2 domain... C2 activity begins via HTTP POST... An additional payload is downloaded from static.<domain>/d/<38 digit string>/<filename>... Detections Behavior MITRE ATT&CK Details AdLoad - ZIP file downloads from unknown domains T1071.001 HTTP
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
macOS adware family delivered by loader malware (ReaderUpdate).
MacOS adware/browser hijacker identified as a secondary payload downloaded from ZIP archives during related suspicious activity.
Genieo is referenced as a named malware family/tag in the content. No further behavioral detail is provided in the excerpt.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.