Bundlore is a macOS adware family and installer framework associated with fake software update lures, especially counterfeit Adobe Flash Player updates, as well as bundling with pirated or low-reputation software. It is one of the more prevalent macOS adware threats and is closely associated in reporting with Shlayer-style distribution chains. Infection commonly relies on user execution of a malicious application bundle or DMG-delivered installer, after which Bundlore downloads, decrypts, and launches additional adware components.
Bundlore has been observed using multi-stage shell-script and Mach-O-based installers that leverage native macOS utilities such as curl, openssl, sqlite3, funzip, killall, and mktemp. Samples have used OpenSSL to decrypt AES-encrypted payloads and have also deobfuscated data with Base64 and RC4. Some variants decode embedded scripts or payloads from within Mach-O binaries, while others use fileless or memory-resident execution routines to decrypt an embedded Mach-O image and load it directly from memory. Reported implementations include dynamic loading of in-memory Mach-O payloads and staging of follow-on application bundles that masquerade as legitimate software.
The malware is notable for browser-focused monetization and manipulation. Bundlore has injected JavaScript into victims’ browsers, used AppleScript to execute JavaScript in active browser tabs, altered browser security settings to facilitate extension installation, and injected advertisements or other content into web pages. It has also used TLS to conceal malicious scripts and related web-injection activity. In some campaigns, Bundlore queried macOS quarantine history via SQLite to inspect recently downloaded files and used process discovery and process-killing behavior to hinder inspection.
Persistence on macOS has been established through LaunchAgents. Bundlore has also used defense-evasion techniques including masquerading malicious application bundles as Flash Player updates, generating temporary staging directories, obfuscating embedded payloads, and in some cases operating partly in memory to reduce on-disk artifacts. The family primarily targets macOS users and is most often linked to adware delivery, browser hijacking, and installation of additional unwanted software rather than traditional espionage objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
AppleScript offers offensive actors a plethora of ways to execute. In addition to simply executing a .scrpt file, you can run AppleScripts from Mail rules, from a shell script, in memory, from the command line, from within a MachO, in a plain text, uncompiled file, from an Automator workflow, from a Folder Action, a Finder Service or from a Calendar event.
many others write their AppleScript directly into a MachO binary, either in plain text strings or in obfuscated base64 or similar encoding. The next sample is a variant of a Pirrit malware... The authors use both plain text AppleScript and base64 encoded AppleScript
executed through user installation of an executable disguised as a flash installer... malware look like Flash Player, Office, or PDF documents... compromised installation files for legitimate software.
Bad Rabbit has masqueraded as a Flash Player installer through the executable file install_flash_player.exe.
MITRE Tactics, Techniques, and Procedures (TTPs) of Bundlore ... Process injection ... Process injection
A majority of binaries in our intelligence systems downloaded the Bundlore payload to the tmp directory using curl request to the C2.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
Several entries explicitly tie host profiling to anti-analysis or execution gating, such as 'DarkGate uses ... disk size and physical memory as part of the malware's anti-analysis checks for running in a virtualized environment,' 'OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks,' and malware terminating or changing behavior based on language or OS/distribution.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Several entries explicitly tie host profiling to anti-analysis or execution gating, such as 'DarkGate uses ... disk size and physical memory as part of the malware's anti-analysis checks for running in a virtualized environment,' 'OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks,' and malware terminating or changing behavior based on language or OS/distribution.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
MITRE Tactics, Techniques, and Procedures (TTPs) of Bundlore ... Web service
55 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
48 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as macOS adware whose shell-script-and-embedded-payload style techniques resemble those used by the analyzed APT32 backdoor.
macOS malware/adware family mentioned as using curl to fetch follow-on payloads without triggering Gatekeeper quarantine enforcement.
macOS malware family delivered via malvertising and fake Flash Player updates. The analyzed component is a Mach-O loader that reconstructs an embedded (stackstring) Python payload, executes it via /usr/bin/python, and ultimately downloads and runs a fresh Bundlore app (mm-install-macos.app) from a remote server.
macOS malware/loader family frequently distributed via malvertising and fake software update lures; typically delivered as repackaged installers/DMGs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.