OSX/Tarmac is a macOS malware family identified by Confiant and commonly referred to as OSX/Tarmac. It was observed as a second-stage payload in malvertising-driven infection chains, notably delivered by OSX/Shlayer and also referenced in a chain where an OSX/Bundlore loader downloaded OSX/Tarmac, which then installed MapperState. The campaign used fake Adobe Flash Player update lures, including a signed disk image named AdobeFlashPlayerInstaller.dmg, and Confiant estimated that up to 5 million visitors may have been exposed in one analyzed campaign. OSX/Tarmac operators were assessed to have begun activity around January or February 2019.
OSX/Tarmac was described as an advanced Objective-C macOS malware implemented in two stages. The first stage acted as a launcher that loaded the second stage from its resources folder with administrator privileges. It attempted privilege elevation by prompting the current administrator for a password and used an encrypted AppleScript passed to NSAppleScript initWithSource: to run with elevated privileges. The malware displayed a WebView mimicking a Flash Player installer, with content fully controlled by its command-and-control server; at the end of the fake installation flow it downloaded and displayed a genuine Adobe Flash Player installer from Adobe servers. Confiant stated that OSX/Tarmac does not establish persistence.
The malware used encrypted strings protected by a custom scheme that first ZLIB-compressed data and then XOR-encrypted it with a hardcoded keystream. It also used the Objective-C bridge to JavaScriptCore and exposed a JSInterface protocol with a SendCommand method; extracted JavaScript showed five commands implemented through its JavaScript command handler. Confiant noted similar slow-debugging and string-decryption-obfuscation techniques in newer versions of OSX/Tarmac.
OSX/Tarmac established encrypted communications with its C2 on launch. Its C2 traffic used a hardcoded 1024-bit RSA public key to encrypt a randomly generated RC2 128-bit key, then used that RC2 key to encrypt exfiltrated data, summarized as base64(hardcodedRSA(randomRC2)+randomRC2(exfiltrated_data)). One of the first exfiltrated packets was TRMC_ComputerInfo_1, which included SessionGuid, SystemVersion, MachineId, PhysicalMemoryInBytes, ProcessorPhysicalCores, ProcessorLogicalCores, and ProcessorFrequencyGHz. It also exfiltrated a base64-encoded command-line parameter field named tfa indicating how it was launched. Extracted client protocol commands included TRMC_Init_2, TRMC_Install_Start_1, TRMC_Install_Success_2, TRMC_Download_Start_1, TRMC_Download_Success_2, TRMC_Error_2, and TRMC_Close_1. Server-side command strings indicated capabilities to download, install, copy, and launch applications. In testing, OSX/Tarmac launched Safari to a traffic.focuusing.com URL that ultimately redirected to an ExpressVPN download page.
Delivery and execution relied on a quarantine-attribute bypass in macOS: OSX/Shlayer used curl to download unsigned OSX/Tarmac payloads, which therefore did not receive quarantine attributes and could bypass Gatekeeper and XProtect checks. This behavior was reported as tested on macOS Mojave 10.14.6. One analyzed OSX/Shlayer variant, OSX/Shlayer.D, used two code-signed applications embedding RSA-encrypted scripts to download and execute OSX/Tarmac. The fake installer sample AdobeFlashPlayerInstaller.dmg had SHA-256 07d0c83caa7af3daaf243168138afd020ce9d7ee9b2f502cbf4acb065f550f73 and was signed with Apple developer certificate 2L27TJZBZM, likely issued to a fake identity named Fajar Budiarto. Confiant identified 52 samples in the wild signed with the same certificate.
OSX/Tarmac has also been linked by Confiant to the broader Hydromac and Mughthesec malware ecosystem. Confiant previously linked OSX/Tarmac to a publicly exposed flashcard app whose commands matched Tarmac malware commands, and later observed overlaps in obfuscation and command structures with MapperState and Hydromac components. Active C2 domains identified for OSX/Tarmac included api[.]updaterbit.com, api[.]topinterfaces.com, api[.]binarysources.com, api[.]alphaelemnt.com, api[.]opticalinput.com, api[.]inettasks.com, api[.]filtercommand.com, api[.]formatlog.com, and api[.]managementexplorer.com. Historical domains included api[.]masterprotocols.com, api[.]logpartition.com, api[.]interfacehelper.com, api[.]bemacexpert.com, api[.]optimizationbit.com, api[.]internetinterop.com, api[.]dynamicmodule.com, api[.]basicinitiator.com, api[.]processformat.com, api[.]upgradedisplay.com, api[.]trustedmode.com, api[.]microstransaction.com, api[.]megamodule.com, api[.]lookupindex.com, api[.]essentialchannel.com, api[.]browserinterop.com, api[.]activeuptodate.com, api[.]futuristmac.com, api[.]flexiblelocator.com, api[.]commonprocesser.com, api[.]highsecuritymac.com, api[.]agentinput.com, api[.]resultsformat.com, api[.]publicanalyser.com, api[.]smarttechupdate.com, api[.]protocolsmart.com, api[.]rotatornet.com, api[.]lookupmanager.com, api[.]interfacesmode.com, api[.]standarteng.com, and api[.]topinterfaces.com.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
MapperState authors used a very confusing method to encrypt their strings to slow down our analysis... This is a classic slow-debugging technique... This block of code is responsible for string decryption and makes a heavy usage of SSE instructions.
that’s not the official Adobe installer but a fake Flash Player installer that was signed using an Apple developer certificate 2L27TJZBZM... Signing malware with Apple developer certificates... became a standard practice for macOS malware developers... the malware is allowed to run after some preliminary checks.
OSX/Tarmac does encrypted communications with the C2 as soon as it is launched... One of the first POST requests will be sent with computer information... The C2 server, after receiving the first encrypted piece of data from OSX/Tarmac, will reply with other encrypted data.
The problem is not all of macOS applications are quarantine aware.. and curl is a one good example... The extended quarantine attribute will not be set for this malware, so none of GateKeeper nor XProtect will kick in... This would be a total bypass of macOS built-in malware security features.
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sophisticated multi-stage macOS malware written in Objective-C and delivered by OSX/Shlayer. It uses encrypted strings and encrypted C2 traffic, gathers host information, can request administrator privileges, loads attacker-controlled web content, and supports downloading, installing, and executing applications or additional payloads.
A macOS malware payload described here as being dropped by Shlayer (i.e., a secondary payload associated with Shlayer activity).
macOS spyware payload reported as being dropped by Shlayer.
macOS malware family used in malvertising infection chains; observed dropping payloads including MapperState and previously delivering a legitimate Adobe Flash Player copy as part of its activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.