OSX/Shlayer

MITRE ATT&CK: S0402 View on attack.mitre.org

Aliases: Zshlayer, Crossrider, OSX/Shlayer

First seen
2018-01-01 00:00:00
Malware type
trojan
Family
Malware family
Operating systems
macos
Profile updated
2026-07-07 15:28:47

Context

OSX/Shlayer is a Trojan designed to install adware on macOS that was first discovered in 2018.

Detection coverage

  • 217 Sigma rules

Malware & tools used

  • Hide Artifacts (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • Linux and Mac Permissions (attack-pattern)
  • Malicious File (attack-pattern)
  • Browser Extensions (attack-pattern)
  • Gatekeeper Bypass (attack-pattern)
  • Unix Shell (attack-pattern)
  • Ignore Process Interrupts (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Resource Forking (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Elevated Execution with Prompt (attack-pattern)

Reports & references

  • MITRE ATT&CK — S0402 (report)
  • blog.malwarebytes.com — New Crossrider Variant Installs Configuration Profiles On Macs (report)
  • blogs.vmware.com — Vmware Carbon Black Tau Threat Analysis Shlayer Macos (report)
  • intego.com — New Osxshlayer Malware Variant Found Using A Dirty New Trick (report)
  • intego.com — Osxshlayer New Mac Malware Comes Out Of Its Shell (report)
  • sentinelone.com — Coming Out Of Your Shell From Shlayer To Zshlayer (report)

External references