Flashback, also known as OSX/Flashback and Flashfake, was a major Mac OS X malware family active in 2011 and 2012 and one of the largest macOS botnet outbreaks of its era. It initially spread by masquerading as an Adobe Flash Player installer and later evolved to use drive-by exploitation of Java vulnerabilities including CVE-2012-0507 and CVE-2011-3544, allowing infection when a user visited a compromised or malicious website hosting a crafted applet. The malware ultimately infected hundreds of thousands of Mac systems worldwide.
On infected hosts, Flashback installed a hidden Mach-O component and established user-level persistence through LaunchAgents. Later stages deployed a malicious dynamic library and abused DYLD_INSERT_LIBRARIES to force that library into browser processes such as Safari. In some variants, browser metadata was modified to ensure the library loaded automatically; in lower-privilege cases, user environment configuration was altered to achieve similar persistence. The injected library interposed CoreFoundation stream functions, enabling interception of both HTTP traffic and HTTPS traffic after decryption within the browser process.
Flashback’s operators used the malware primarily for web-traffic manipulation and ad-fraud-like activity. The malware collected Google search-related data and system identifiers, communicated with command-and-control infrastructure, and could alter web responses to simulate advertisement clicks. It supported resilient command-and-control through hard-coded and generated domains, cryptographic validation of downloaded payloads and server identities using embedded RSA keys, and a fallback discovery mechanism based on Twitter hashtags. The family also employed layered obfuscation and host-bound encryption, including RC4 keyed to the victim Mac’s hardware or platform UUID, which complicated off-host analysis. Some variants checked for security tools and removed themselves if analysis or monitoring software was present.
Flashback is closely associated with the 2012 Java exploitation wave against Apple systems and is notable for demonstrating large-scale botnet operations on Mac OS X. Apple later issued Java updates and a dedicated removal tool to mitigate infections.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Flashback is a threat on the OS X platform which was detected for the first time in the fall of 2011. After staying unnoticed for several months, Flashback attracted general attention in April 2012 by managing to infect over 500,000 computers.
Flashback is a threat on the OS X platform which was detected for the first time in the fall of 2011. After staying unnoticed for several months, Flashback attracted general attention in April 2012 by managing to infect over 500,000 computers.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The method which has been by far the most effective at propagating Flashback infection was one that exploits one of two flaws in Java: CVE-2012-0507 or CVE-2011-3544. In this case, the vulnerabilities lead Flashback to an automatic installation without the knowledge or input of the user, simply by visiting a website containing the malicious Java applet, either directly or via an Iframe.
com.sun.jsched.plist (from ~/Library/LaunchAgents/com.sun.jsched.plist ... <key>ProgramArguments</key><array><string>/Users/USERNAME/.jsched</string></array><key>RunAtLoad</key><true/><key>StartInterval</key><integer>4212</integer>
The sole purpose of this executable file is the downloading and installation of a web traffic interception component.
The method which has been by far the most effective at propagating Flashback infection was one that exploits one of two flaws in Java: CVE-2012-0507 or CVE-2011-3544.
The second method of infection which has been identified, however, used a Java-signed applet. By visiting a malicious website, the victim receives a message from the Java interpreter requesting permission to run an applet that claims to be signed by Apple... As a result of authorization given by the user, the Mac is infected.
The first variants masqueraded as an update of Adobe Flash player. The victim is directed to a malicious website... downloads and runs the offered file. By entering his password, as requested during the installation, the victim allows Flashback to proceed to self-install on his Mac.
com.sun.jsched.plist (from ~/Library/LaunchAgents/com.sun.jsched.plist ... <key>ProgramArguments</key><array><string>/Users/USERNAME/.jsched</string></array><key>RunAtLoad</key><true/><key>StartInterval</key><integer>4212</integer>
Specifically, it modified Safari’s Info.plist file, adding a DYLD_INSERT_LIBRARIES entry that referenced its malicious payload.
A plist file (Property List File) is created in ~/Library/LaunchAgents to run the command each time the user logs onto the infected computer.
If it does not have administrator privileges, Flashback will add one to the file ~/.MacOSX/environement.plist. It takes care of the creation of one if it does not exist... When the user logs in, the variable will be affected; therefore the library will be loaded in all applications which will be started by that user.
com.sun.jsched.plist (from ~/Library/LaunchAgents/com.sun.jsched.plist ... <key>ProgramArguments</key><array><string>/Users/USERNAME/.jsched</string></array><key>RunAtLoad</key><true/><key>StartInterval</key><integer>4212</integer>
Specifically, it modified Safari’s Info.plist file, adding a DYLD_INSERT_LIBRARIES entry that referenced its malicious payload.
A plist file (Property List File) is created in ~/Library/LaunchAgents to run the command each time the user logs onto the infected computer.
If it does not have administrator privileges, Flashback will add one to the file ~/.MacOSX/environement.plist. It takes care of the creation of one if it does not exist... When the user logs in, the variable will be affected; therefore the library will be loaded in all applications which will be started by that user.
when it is first run, the malware sends the Platform UUID from the infected system to the Command and Control (C&C) server over HTTP.
In the key 0x92fa, we see a list of paths to anti-virus software, firewall software or software intended for the use of experienced users. If one of these files exists on the infected system, the execution will end and the malware will uninstall itself from the system.
When it comes to a search query sent to Google, the search keywords as well as information on the machine such as the Platform UUID and the language configured are sent to the command and control server.
It therefore seems we are facing self-encrypting malware... the author has implemented the RC4 algorithm to decrypt the content using the Platform UUID as the key.
In the configuration we can find an URL to search for a hashtag on Twitter... another technique available to the botmaster to manage his or her Botnet.
when it is first run, the malware sends the Platform UUID from the infected system to the Command and Control (C&C) server over HTTP... Periodically, the malicious software polls a list of domains from which it can download and run a file.
Periodically, the malicious software polls a list of domains from which it can download and run a file... The only thing that we have seen being downloaded by the installation component is a network traffic interception component.
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
macOS malware that modified Safari’s Info.plist to set DYLD_INSERT_LIBRARIES so a malicious dylib loaded into Safari and interposed network APIs for ad-fraud-like browser traffic manipulation.
Referenced only as a comparison point for sophistication among non-Windows trojans.
Mac-specific trojan that was spread using Java vulnerability CVE-2011-3544.
OS X malware referenced as part of a presentation update; mentioned in the context of older malware and associated tricks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.