VeryMal is a prolific malvertising threat actor associated with large-scale fake Adobe Flash Player update campaigns that primarily targeted macOS users and delivered the Shlayer malware family, including later second-stage payloads such as OSX/Tarmac. The actor is known for abusing online advertising redirect chains to selectively route victims to fraudulent update pages and for operating at significant scale, with exposure estimates reaching millions of user sessions. VeryMal’s operations have shown sustained technical evolution. Earlier activity used steganography-based ad payloads, while later campaigns shifted to subtler JavaScript delivery mechanisms, including abuse of cloud-hosted backend services to retrieve and execute malicious code dynamically. The actor employed browser and environment fingerprinting to identify suitable victims, particularly Safari on macOS, and used anti-analysis and anti-debugging measures to hinder inspection. Code-level overlaps across campaigns, including shared implementation artifacts and infrastructure patterns, link these operations to the same actor. In campaigns delivering Shlayer and OSX/Tarmac, VeryMal used fake installer lures and code-signed macOS components to improve execution success. The intrusion chain included downloading additional payloads in ways that bypassed macOS quarantine-based protections, followed by execution of an unsigned second stage. OSX/Tarmac demonstrated comparatively advanced tradecraft for adware-oriented macOS malware, including encrypted strings, Objective-C and JavaScriptCore-based command handling, AppleScript-assisted privilege elevation, and encrypted command-and-control communications. Observed functionality included system profiling, downloading and launching applications, and exfiltrating host information. Available reporting does not indicate that OSX/Tarmac established persistence. VeryMal appears to be financially motivated. The actor’s campaigns centered on malvertising, fake software updates, traffic redirection, and delivery of malware associated with monetization and downstream payload distribution rather than espionage or destructive objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
42 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malvertising operator behind a large macOS campaign delivering OSX/Shlayer, which in turn downloads and executes OSX/Tarmac via fake Adobe Flash Player update lures.
Malvertising actor running large-scale fake Flash update campaigns that redirect users via ads and deliver Shlayer malware on macOS. The group evolved delivery mechanisms from steganography-based payloads to Firebase/Firestore-hosted JavaScript, with fingerprinting, obfuscation, anti-debugging, and rapid infrastructure pivots.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.