Researchers reported that the macOS adware family OSX.Pirrit used fake installers posing as Adobe Flash Player to trick users into granting administrative access, then downloaded additional components from remote infrastructure. One analyzed .pkg sample was a script-only installer with almost no embedded payload; its postinstall script retrieved an archive from c.firstinstallmac[.]club, unpacked it in /var/tmp, executed the downloaded binary, and deleted the artifacts afterward. The installer also collected host details including the macOS version and hardware UUID, and added a special URL parameter for systems running macOS 10.12.
The campaign was described as a more advanced Pirrit variant capable of obtaining root privileges, persisting on infected Macs, monitoring user activity, and hijacking browsers to serve ads. Researchers said the malware had infected tens of thousands of Macs and in some cases used AppleScript to inject advertisements directly into browsers, complicating removal compared with older proxy-based methods. The script-only packaging approach was also noted in WizardUpdate, suggesting operators used lightweight installers to evade static detection and swap delivered malware on demand.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
The installer analysis concluded that script-only packaging had been observed in both Pirrit and WizardUpdate adware families, enabling operators to fetch executable content at install time and potentially evade static detection or swap payloads on demand.
Analysis of a Pirrit-associated macOS PKG sample showed it masqueraded as Adobe Flash Player while containing no meaningful embedded payload. Instead, its postinstall script collected the host macOS version and hardware UUID, downloaded a remote archive from c.firstinstallmac[.]club, executed the retrieved binary from /var/tmp, and then deleted the artifacts.
TargetingEdge sent cease-and-desist letters seeking to deter publication of Amit Serper's research linking the company to OSX.Pirrit. Cybereason proceeded with publication despite the legal threats, while the company denied any connection to the malware.
Cybereason published research on a more advanced OSX.Pirrit variant that could obtain root privileges, persist on infected Macs, spy on user activity, and inject ads into browsers via AppleScript. Serper said the malware remained highly active and had infected tens of thousands of Macs.
Amit Serper said he had tracked OSX.Pirrit and its variants for over a year, establishing a long-running investigation into the macOS adware family.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.