Shlayer is a macOS trojan downloader first identified in February 2018. It primarily provides first-stage infection by downloading, unpacking, and executing additional payloads, especially adware families including Bundlore, Cimpli, Pirrit, and AdLoad. Shlayer has also delivered Tarmac. Its campaigns are predominantly associated with advertising fraud; downstream adware injects advertisements, manipulates browser searches, and redirects traffic.
Distribution relies heavily on malvertising, malicious websites, hijacked or expired domains, and fraudulent software-update pages, historically impersonating Adobe Flash Player. Affiliate networks distribute malicious links through websites, video descriptions, and references on legitimate services. Entertainment-themed lures and cracked-software sites also facilitate distribution. VeryMal and Yosec are established malvertising operators associated with Shlayer delivery. Infections affect macOS users broadly, including U.S. K–12 educational institutions.
Variants use Bash, Zsh, Python, or Mach-O executables, commonly packaged in disk images. Shlayer collects system identifiers and the operating-system version, retrieves secondary payloads, makes them executable, and launches them using native macOS utilities. Observed implementations obscure scripts and configuration through encryption and layered obfuscation; the Shlayer.F variant conceals AES-encrypted configuration within a modified disk-image structure. Some variants remove downloaded archives and staging artifacts after execution. Shlayer has used Launch Item persistence and techniques that bypass macOS execution protections, including exploitation of the Gatekeeper bypass CVE-2021-30657. Malicious Shlayer code also obtained Apple notarization in 2020, enabling execution under default Gatekeeper settings.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2021-30657 April 26 macOS Gatekeeper bypass abused by Shlayer malware
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Feb 2020 Campaign: 모래종이(Sandpaper) ... Observed commodity malware: Shlayer and Mirai bot.
The bad actor is known for running large scale fake Flash update campaigns that are hosted on .icu domains by way of display ad auto-redirects: VeryMal Fake Flash Update — Shlayer Trojan
Yosec — ... They are a major source of distribution for the notorious Shlayer trojan: OSX/Shlayer ...
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Note the decrypted string that corresponds to commands, OSX/Shlayer.F executes them via popen() function.
The malicious shell scripts used by Shlayer and Bundlore are usually malvertising-focused adware bundlers using shell scripts in the kill chain to download and install an adware payload.
The most recent Shlayer variant is Trojan-Downloader.OSX.Shlayer.e... written in Python rather than Bash... the seemingly standard installer turns out to be a Python script.
After unpacking the archive, the main Python script uses the chmod tool to assign the file 84cd5bba3870 permission to run in the system. After that, the trojan runs the downloaded and unpacked application package using the built-in open tool.
The bash script in these variants decrypt the next stage encrypted blobs containing the next stage bash scripts using openssl with base64, Advanced Encryption Standard (AES), CBC (Cipher Block Chaining) to thwart security scanners.
Shlayer is a trojan downloader, which spreads via fake applications that hide its malicious code... Cimpli masquerades as a useful Mac utility (i.e., “Any Search”).
After that, the Trojan runs the downloaded and unpacked application package using the built-in open tool, and deletes the downloaded archive and its unpacked contents.
encrypted string ref in function 0x100020a50 decoded to : defaults read /System/Library/CoreServices/SystemVersion.plist ProductVersion
Next, the main script generates a unique user and system ID, and also collects information about the version of macOS in use.
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as commodity macOS malware whose techniques were echoed or improved upon by the APT32 backdoor delivery chain.
macOS malware family cited as using LaunchAgents/LaunchDaemons for persistence.
macOS malware family cited as using curl to download secondary payloads and bypass Gatekeeper by avoiding quarantine attributes.
A Mac-focused trojan delivered via fake Flash update malvertising campaigns and auto-redirects. In this report, the campaign uses Firebase/Firestore-hosted payloads, fingerprinting, obfuscation, and redirects to deliver the Shlayer binary.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.