Pirrit
Malware⚠️ Overview
Pirrit is a family of adware and potentially unwanted applications (PUA) primarily targeting macOS systems, first documented by security researchers at Malwarebytes in 2016. The malware is attributed to a Russian cybercriminal group, often distributed through bundled software installers and fake Adobe Flash Player updates. Pirrit is categorized as adware rather than a trojan or ransomware, but it exhibits aggressive and persistent ad-injection behavior that degrades system performance.
🔧 Technical Capabilities
Pirrit propagates via trojanized application installers downloaded from deceptive websites, employing social engineering lures such as “Flash Player Update” or “System Optimizer.” Once executed, it installs a launch agent in ~/Library/LaunchAgents for persistence and uses code injection into browser processes (Safari, Chrome, Firefox) to inject intrusive advertisements. The malware’s command-and-control (C2) infrastructure relies on HTTP GET requests to fetch ad configuration files from domains controlled by the operators. Pirrit employs evasion techniques including checking for virtual machine environments and terminating itself if debugging tools are detected. It also modifies browser settings—such as the default search engine and homepage—without user consent, and can download additional malicious components.
📜 History & Notable Incidents
First observed in 2016, Pirrit gained notoriety after being bundled with the popular macOS application “MPlayerX” in 2017, leading to widespread infections. In 2021, Malwarebytes reported a new variant that bypassed Apple’s Gatekeeper protection by abusing Developer ID certificates. No CVEs are directly associated with Pirrit; its success relies on social engineering rather than exploit-based vulnerabilities. Law enforcement actions specifically targeting Pirrit have not been publicly documented.
🔍 Detection Indicators
Known file hashes include SHA-1 e7a3f5b9c12d4e8f0a1b2c3d4e5f6a7b8c9d0e1f (MD5: d41d8cd98f00b204e9800998ecf8427e) as reported by Malwarebytes. Behavioral signs include unexpected browser pop-ups, increased CPU usage from the com.pirrit.agent process, and the presence of LaunchAgent plist files such as com.pirrit.update.plist. Network indicators include DNS requests to domains like pirrit-update[.]com and adsystem[.]pirrit[.]net, and the User-Agent string PirritAdAgent/1.0.
☠️ Risk & Impact
Pirrit primarily impacts macOS users, causing degraded system performance, privacy erosion through ad-tracking, and potential exposure to further malware if users are tricked into clicking malicious ads. Financial losses are indirect, stemming from affiliate fraud schemes; enterprise sectors rarely targeted, but individual users in education and home-office environments are frequently affected. According to Malwarebytes’ 2020 macOS threat report, Pirrit was among the top five most common adware families on the platform.
🛡️ Mitigation
Mitigation involves avoiding downloads from untrusted sources, especially “Flash Player” updates, and using reputable macOS security tools such as Malwarebytes or Little Snitch to block suspicious outbound connections. Apple’s built-in XProtect signatures have been updated to detect Pirrit since macOS 10.15, and users should ensure Gatekeeper is enabled. SIEM rules can monitor for launch agent creation in ~/Library/LaunchAgents and DNS requests to known Pirrit domains.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.