Shlayer

First seen
2018-02-01 00:00:00
Malware type
trojan, dropper
Family
Malware family
Profile updated
2026-07-07 13:44:32

Targeted industries: media-and-entertainment technology-and-telecommunications

Context

According to PCrisk, Shlayer is a trojan-type virus designed to proliferate various adware and other unwanted applications, and promote fake search engines. It is typically disguised as a Adobe Flash Player installer and various software cracking tools. In most cases, users encounter this virus when visiting dubious Torrent websites that are full of intrusive advertisements and deceptive downloads.

Reports & references

  • CISA — Aa20 345A (report)
  • cisecurity.org — Top 10 Malware March 2022 (report)
  • CrowdStrike — How Crowdstrike Analyzes Macos Malware To Optimize Automated Detection Capabilities (report)
  • malpedia.caad.fkie.fraunhofer.de — Osx.Shlayer (report)
  • threatpost.com — 152146 (report)
  • Kaspersky — 95724 (report)
  • CrowdStrike — Shlayer Malvertising Campaigns Still Using Flash Update Disguise (report)
  • cedowens.medium.com — Macos Gatekeeper Bypass 2021 Edition 5256A2955508 (report)
  • resource.redcanary.com — 2021 Threat Detection Report (report)
  • objective-see.com — Blog 0X64 (report)
  • jamf.com — Shlayer Malware Abusing Gatekeeper Bypass On Macos (report)

External references