OSX/Shlayer
MITRE ATT&CK: S0402 View on attack.mitre.org
Aliases: Zshlayer, Crossrider, OSX/Shlayer
- First seen
- 2018-01-01 00:00:00
- Malware type
- trojan
- Family
- Malware family
- Operating systems
- macos
- Profile updated
- 2026-07-07 15:28:47
Context
OSX/Shlayer is a Trojan designed to install adware on macOS that was first discovered in 2018.
Detection coverage
- 217 Sigma rules
Malware & tools used
- Hide Artifacts (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- Linux and Mac Permissions (attack-pattern)
- Malicious File (attack-pattern)
- Browser Extensions (attack-pattern)
- Gatekeeper Bypass (attack-pattern)
- Unix Shell (attack-pattern)
- Ignore Process Interrupts (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Resource Forking (attack-pattern)
- File and Directory Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Elevated Execution with Prompt (attack-pattern)
Reports & references
- MITRE ATT&CK — S0402 (report)
- blog.malwarebytes.com — New Crossrider Variant Installs Configuration Profiles On Macs (report)
- blogs.vmware.com — Vmware Carbon Black Tau Threat Analysis Shlayer Macos (report)
- intego.com — New Osxshlayer Malware Variant Found Using A Dirty New Trick (report)
- intego.com — Osxshlayer New Mac Malware Comes Out Of Its Shell (report)
- sentinelone.com — Coming Out Of Your Shell From Shlayer To Zshlayer (report)