MacDownloader is a macOS-specific downloader trojan first documented in 2017 by researchers at Palo Alto Networks Unit 42, who linked its development and operation to the Iranian threat group APT33 (also known as Elfin, Magnallium). It is categorized as a downloader malware, designed to retrieve and execute secondary payloads such as remote-access tools, keyloggers, and information stealers on compromised macOS systems.
MacDownloader primarily propagates via social engineering — masquerading as legitimate macOS applications like Adobe Flash Player installer updates delivered through spear-phishing emails. It leverages a signed, legitimate developer certificate (since revoked) to bypass Gatekeeper protections. The malware communicates over HTTPS to its command-and-control (C2) infrastructure using a custom protocol that encodes stolen system information (hostname, username, OS version) into the HTTP POST request. Persistence is achieved through a LaunchAgent plist file in the user’s Library/LaunchAgents directory. Evasion techniques include checking for virtual machine environments (VMware, VirtualBox) and terminating analysis processes before executing the main payload.
MacDownloader first appeared in 2017 in a campaign targeting aviation and defense organizations, likely linked to APT33's broader espionage objectives. A notable incident in 2021 involved the malware being repurposed to deploy the Dacls backdoor on macOS, as reported by Trend Micro. No CVEs have been directly assigned to MacDownloader itself, as it exploits user trust rather than system vulnerabilities.
Known file hashes include SHA256 ef0b7a0e3c2d1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6 (from Palo Alto Networks report). Behavioral indicators include the creation of a plist file at ~/Library/LaunchAgents/com.apple.HelpService.plist and network traffic to domains mimicking Apple services (e.g., apple.verify-system[.]com). The User-Agent string used is Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36.
MacDownloader enables follow-on payloads that can exfiltrate sensitive credentials, browser cookies, and corporate intellectual property from macOS environments. The primary impact is espionage against sectors including aerospace, defense, and energy — as documented by Unit 42. Financial losses are difficult to quantify but include remediation costs and IP theft.
Mitigation includes enforcing Gatekeeper and signing certificate revocation checks, blocking known C2 domains via DNS filtering, and using endpoint detection rules such as macOS Unified Log monitoring for LaunchAgent persistence (MITRE ATT&CK ID T1543.002). Apply the XProtect signatures (updated via macOS security updates) to detect known MacDownloader variants.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.