OSX/Shlayer

Malware

⚠️ Overview

OSX/Shlayer is a macOS trojan downloader and adware family first documented in February 2018 by Intego and later extensively analyzed by Objective-See and Trend Micro. It is primarily operated by financially motivated threat actors who distribute it through fake Flash Player updates, fake installers for popular macOS applications, and malvertising campaigns. Shlayer is categorized as a downloader for adware and potentially unwanted programs (PUPs) rather than a ransomware, RAT, or botnet.

🔧 Technical Capabilities

Shlayer propagates mainly via compromised websites hosting fake browser update prompts or via malvertising that redirects users to malicious gateways. It uses a multistage infection chain: first a shell script or DMG file is downloaded, which then fetches the second-stage payload (often a zip archive containing a Mach-O binary) from hardcoded or dynamically resolved C2 servers. Persistence is established through LaunchAgents (plist files in ~/Library/LaunchAgents) or via cron jobs. Evasion techniques include checking for sandbox environments (e.g., detecting virtual machines like Parallels or VMware) and using obfuscated JavaScript in the initial gateways. C2 communication is typically over HTTPS, using domains generated via domain-generation algorithms (DGAs) or hardcoded IP addresses; some variants also use DGA to rotate domains weekly. The payload often includes XOR-encrypted configuration data and can deliver additional adware families like Bundlore or Genieo.

📜 History & Notable Incidents

OSX/Shlayer was first publicly identified in 2018 by Patrick Wardle (Objective-See) during a macOS malware sample analysis. By 2022, it had been one of the most prevalent macOS malware families, with detections reported by Malwarebytes affecting millions of users globally. No specific high-profile victims or CVEs are directly attributed to Shlayer; it rarely exploits vulnerabilities but relies on social engineering (fake Flash updates). Law enforcement actions have been limited, though Apple has updated Gatekeeper and Notarization policies to block some of the signer certificates used by Shlayer samples.

🔍 Detection Indicators

Known file hashes are not widely published by vendors due to rapid mutation, but behavioral indicators include: execution of shell scripts downloading suspicious DMG or ZIP archives; creation of LaunchAgent plists containing URLs to remote payloads; and network connections to domains like [random].me or [random].com that resolve frequently. Additional IOCs include suspicious User-Agent strings such as Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36 used during fake update requests. Threat intelligence reports from Intego (2018) and Trend Micro (2020) provide sample indicators.

☠️ Risk & Impact

Shlayer does not directly exfiltrate sensitive data or cause system damage, but its adware payloads can degrade system performance, inject intrusive advertisements, and redirect search traffic to affiliate marketing pages. The primary financial impact comes from affiliate fraud and pay-per-install schemes. Affected sectors are broad, targeting any macOS user who visits compromised or malicious websites, with a focus on entertainment, software download, and adult content sites.

🛡️ Mitigation

Defensive measures include enabling Gatekeeper and notarization checks, avoiding unofficial download sources for Flash Player or other applications, and deploying endpoint detection rules that flag scripts executed from /tmp or ~/Downloads connecting to newly registered domains. Security tools like Malwarebytes for Mac and Objective-See's KnockKnock and BlockBlock can detect persistence mechanisms. No specific patches apply as Shlayer does not exploit vulnerabilities; user education against fake update prompts is critical.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.