MapperState is a macOS malware family identified by Confiant/ConfiantIntel and observed in malvertising-driven infection chains targeting Apple Silicon (M1) systems. It was seen on major U.S. publisher websites as part of a multi-stage chain in which an ARM-compatible, Apple-notarized OSX/Bundlore loader downloaded OSX/Tarmac, which then installed MapperState. MapperState communicates with the C2 domain mapperstate[.]com and persists as a LaunchDaemon via com.MapperState.system.plist, configured to run the executable MapperState.system at load.
Analysis described MapperState as heavily obfuscated: the sample contained roughly 943 functions with stripped symbols, few identifiable strings, and repeated string-decryption logic copied into about 198 code blocks to slow reverse engineering. Imported functionality and decrypted strings indicated process creation and HTTP communications, and showed that MapperState can download and execute additional programs, making it primarily a downloader for follow-on malware. Decrypted strings also showed checks for installed antivirus products. During analysis, the C2 returned empty content, so the next-stage payload could not be identified.
Confiant linked MapperState to the broader Hydromac malware ecosystem. Decrypted command strings matched Hydromac Root Agent naming conventions (HM_RA_*), and researchers confirmed the command HM_RA_Init_1 was sent to the C2. Reporting assessed MapperState to be a Hydromac Root Agent related to OSX/Tarmac and the older macOS malware Mughthesec, based on overlaps in command strings, functionality, and infrastructure. A related Hydromac Agent sample communicated with api[.]mughthesec.com, a domain previously associated with Mughthesec. High-confidence indicators mentioned in the reporting include mapperstate[.]com, api[.]mughthesec.com, SHA-256 919d049d5490adaaed70169ddd0537bfa2018a572e93b19801cf245f7fd28408 for the analyzed MapperState sample, and SHA-256 7f7c7e1b181142592b2f8b7c823a969fb79160c9a5920abd718364eae98d1496 for a related Hydromac Agent sample.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
MapperState authors used a very confusing method to encrypt their strings to slow down our analysis... This is a classic slow-debugging technique... This block of code is responsible for string decryption and makes a heavy usage of SSE instructions.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
macOS malware component described as a Hydromac 'Root Agent' that persists as a LaunchDaemon (com.MapperState.system.plist) and communicates with a C2 (mapperstate[.]com). Uses extensive string encryption/obfuscation (many duplicated decryption blocks) to hinder analysis; appears to download/execute additional payloads and checks for installed AV products.
macOS malware targeting Apple M1 systems that persists as a launch daemon, communicates with a C2 server, checks for installed AV products, and downloads and executes additional payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.