Bundlore

MITRE ATT&CK: S0482 View on attack.mitre.org

Aliases: OSX.Bundlore, SurfBuyer, Bundlore

First seen
2015-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
macos
Related IoCs
125 (21 malicious)
Last IoC activity
2026-09-01 20:33:00
Profile updated
2026-07-07 13:44:53

Context

Bundlore is adware written for macOS that has been in use since at least 2015. Though categorized as adware, Bundlore has many features associated with more traditional backdoors.

Recent IoC activity

21 malicious indicators in Maltiverse are attributed to Bundlore (S0482). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname pixeltrack.eyeviewads.com 2026-09-03 2
hostname mailruupdater.cdnmail.ru 2026-09-03 3
hostname goappsdl.distribmail.ru 2026-09-03 2
hostname dlg-messages.buzzrin.de 2026-09-03 3
hostname dlg-configs.buzzrin.de 2026-09-03 3
hostname xtnmailru.cdnmail.ru 2026-09-03 3
hostname spotx-sync.nuggad.net 2026-09-03 1
hostname www.audacity.de 2026-06-25 3
file sample tourboy-3.3.1-setup.exe 2026-04-15 1
file sample DivXInstaller_master.exe_ 2026-04-13 1
file sample binary 2026-04-12 1
file sample audacity.php 2026-04-07 1
file sample Dingtone Credits Generator.exe 2026-03-28 1
file sample Dotefut.exe 2026-02-08 1
file sample 72BCE11F7770CB583DEAA5110F76AB1B8E96E50A.{PE} 2026-01-27 1
file sample synctask_bf95af618a8e44b2a9aa92a6bd742e86514e893a4ea336bd7ca8a58f3b5f5c97_32135.exe_ 2026-01-27 1
file sample rariseba.exe 2026-01-27 1
file sample go_bundle.exepartner_new_urlhttp3A2F2Funiversallnk.com2Fapi2Fgoal3fvisitid3dk... 2026-01-09 1
hostname kapulainen.ru 2025-11-11 2
file sample farmers-dynasty-v0_69_PDA3AF.exe 2025-11-11 1

Detection coverage

  • 522 Sigma rules

Malware & tools used

  • Exfiltration Over Alternative Protocol (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Process Discovery (attack-pattern)
  • Unix Shell (attack-pattern)
  • Hide Artifacts (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • SSH Authorized Keys (attack-pattern)
  • Python (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Launch Agent (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Software Discovery (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • Malicious File (attack-pattern)
  • Launch Daemon (attack-pattern)
  • Browser Extensions (attack-pattern)
  • AppleScript (attack-pattern)
  • JavaScript (attack-pattern)
  • Linux and Mac Permissions (attack-pattern)
  • Web Protocols (attack-pattern)

Reports & references

  • ESET — Eset Threat Report Q22020 (report)
  • malpedia.caad.fkie.fraunhofer.de — Osx.Bundlore (report)
  • labs.sentinelone.com — Resourceful Macos Malware Hides In Named Fork (report)
  • Trend Micro — Nukesped Copies Fileless Code From Bundlore Leaves It Unused (report)
  • twitter.com — 1393215825931288580 (report)
  • blog.confiant.com — New Macos Bundlore Loader Analysis Ca16D19C058C (report)
  • MITRE ATT&CK — S0482 (report)
  • mackeeper.com — 610 Macos Bundlore Adware Analysis (report)

External references