Bundlore
MITRE ATT&CK: S0482 View on attack.mitre.org
Aliases: OSX.Bundlore, SurfBuyer, Bundlore
- First seen
- 2015-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- macos
- Related IoCs
- 125 (21 malicious)
- Last IoC activity
- 2026-09-01 20:33:00
- Profile updated
- 2026-07-07 13:44:53
Context
Bundlore is adware written for macOS that has been in use since at least 2015. Though categorized as adware, Bundlore has many features associated with more traditional backdoors.
Recent IoC activity
21 malicious indicators in Maltiverse are attributed to Bundlore (S0482). The 20 most recently updated:
Detection coverage
- 522 Sigma rules
Malware & tools used
- Exfiltration Over Alternative Protocol (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- System Information Discovery (attack-pattern)
- Process Discovery (attack-pattern)
- Unix Shell (attack-pattern)
- Hide Artifacts (attack-pattern)
- Drive-by Compromise (attack-pattern)
- SSH Authorized Keys (attack-pattern)
- Python (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Launch Agent (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Software Discovery (attack-pattern)
- GUI Input Capture (attack-pattern)
- Malicious File (attack-pattern)
- Launch Daemon (attack-pattern)
- Browser Extensions (attack-pattern)
- AppleScript (attack-pattern)
- JavaScript (attack-pattern)
- Linux and Mac Permissions (attack-pattern)
- Web Protocols (attack-pattern)
Reports & references
- ESET — Eset Threat Report Q22020 (report)
- malpedia.caad.fkie.fraunhofer.de — Osx.Bundlore (report)
- labs.sentinelone.com — Resourceful Macos Malware Hides In Named Fork (report)
- Trend Micro — Nukesped Copies Fileless Code From Bundlore Leaves It Unused (report)
- twitter.com — 1393215825931288580 (report)
- blog.confiant.com — New Macos Bundlore Loader Analysis Ca16D19C058C (report)
- MITRE ATT&CK — S0482 (report)
- mackeeper.com — 610 Macos Bundlore Adware Analysis (report)