The Flashback malware infected more than 500,000 Mac systems—and by some estimates more than 600,000—after evolving from fake Adobe Flash Player installers to drive-by compromise via malicious Java applets. Researchers tied the largest wave to exploitation of Java flaws including CVE-2012-0507 and CVE-2011-3544, which allowed compromised websites to silently drop malware on vulnerable OS X hosts. Doctor Web said its telemetry showed about 817,879 bots had connected at some point, with roughly 550,000 systems still checking in during a 24-hour period and around 650,000 remaining infected overall, disputing lower public estimates.
Technical analysis showed Flashback used a hidden Mach-O installer, persistence via a plist, and a second-stage library that intercepted HTTP and HTTPS traffic by abusing DYLD_INSERT_LIBRARIES and CoreFoundation stream interposition. The malware encrypted components with RC4 keys derived from each victim Mac’s Platform or Hardware UUID, generated large numbers of domains for command-and-control, validated updates with hard-coded RSA signatures, and even used a Twitter hashtag fallback for C2 discovery. Its operators appeared focused on ad fraud and traffic manipulation, including harvesting Google search-related data and altering responses to simulate ad clicks, while Apple later issued Java patches and a dedicated removal tool to contain the outbreak.

Pull IOCs and campaign context straight into your stack.
15 events from the most recent confirmed update back to the earliest known activity.
On April 20, 2012, Doctor Web said roughly 650,000 Macs were still infected and about 817,879 bots had connected to the botnet at some point. It attributed lower public estimates to a third-party-controlled server at 74.207.249.7 that stalled infected hosts after they connected.
On April 17, 2012, Doctor Web recorded 714,483 unique IP addresses and 582,405 Mac UUIDs on the BackDoor.Flashback.39 botnet. The company said new previously unregistered infected computers were still joining daily.
On April 16, 2012, Doctor Web recorded 717,004 unique IP addresses and 595,816 Mac UUIDs on the BackDoor.Flashback.39 botnet. The figures reflected continued large-scale infection despite reports of decline.
Doctor Web registered additional date-generated Flashback domains on April 16, 2012. The company said this improved the accuracy of botnet size calculations because all BackDoor.Flashback.39 variants used those domains.
On April 12, 2012, a Contagio post update added another Flashback-related binary (sv.4), the com.sun.jsched.plist persistence mechanism, associated domains, and an Emerging Threats detection signature. The post provided concrete indicators and behavioral details for Flashback.K analysis and detection.
Apple released a Mac OS X Java update containing Oracle's fix on April 3, 2012. By then, Flashback had already infected about 600,000 Macs according to cited reporting.
In early April 2012, Dr. Web reported that a modified BackDoor.Flashback.39 variant had infected more than 600,000 Mac computers and formed a major botnet. Kaspersky Lab confirmed Dr. Web's findings one day later.
F-Secure first detected the later Flashback variant that spread via a Java vulnerability in April 2012. This variant enabled drive-by infection through malicious or compromised websites.
At the beginning of April 2012, Doctor Web registered the main command-and-control domains used by BackDoor.Flashback.39. This sinkholing effort was part of measuring and disrupting the botnet.
Oracle fixed the Java vulnerability later exploited by Flashback on February 14, 2012. Apple had not yet shipped the corresponding Mac OS X Java update at that time.
The first known Flashback variant was discovered by Intego in September 2011. Early variants infected Mac users by masquerading as an Adobe Flash Player installer.
As of January 9, 2014, about 22,000 Macs were still reportedly infected with Flashback. This showed the malware persisted on some systems long after Apple's updates and removal efforts.
Apple issued a further update on April 12, 2012, to remove the most common Flashback variants. The removal utility was made available for Lion, Snow Leopard, and Intel versions of Leopard.
VirusTotal recorded analysis of the Flashback.O sample on 2012-04-11 01:15:36 UTC, with 19 of 42 engines detecting it as Flashback-, Flashfake-, or related Mac malware. The sample was identified as a Mach-O fat binary executable.
A Flashback.O payload binary taken from a victim machine was uploaded anonymously a few hours after a prior post about Flashback.K. The sample was notable because it was a payload rather than an installer or downloader.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 57 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
news.drweb.com
Open sourcecontagiodump.blogspot.com
Open sourcecontagiodump.blogspot.com
Open sourceen.wikipedia.org
Open sourceweb-assets.esetstatic.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.