Skip to main content

Shlayer Malware Continues To Attack Mac Systems

By February 3, 2020May 9th, 2022Cybersecurity

If you’re a Mac user, you may have heard of the malware known as Shlayer. It first made headlines in the early part of 2018.

The malware is primarily used to install malicious adware on infected systems that spam an unreasonable number of popups. The popups generate ad revenue for the malware’s controllers.

The malicious code recently celebrated its second birthday, and the hackers who developed it have been busy in that time. According to statistics gathered by Kaspersky Lab, Shlayer has found its way onto one in ten Mac systems, making it the most widely spread MacOS malware threat.

Shlayer finds its way onto target machines via a staggering variety of roads. Researchers have uncovered more than 700 poisoned domains that host the code. The code is linked to a wide range of legitimate websites including YouTube and in the footnotes of a variety of Wikipedia articles.

The main method of distribution, however, is via fake Flash Player updates that have infiltrated literally thousands of websites. The malicious code is also often found on websites that illegally stream sporting events and television shows. The illegal websites conveniently often feature ads that inform site visitors that they need to download a Flash update in order to watch the content they’re interested in viewing.

One of the security researchers at Kaspersky Lab, Anton Ivanov, had this to say about the matter:

The macOS platform is a good source of revenue for cybercriminals, who are constantly looking for new ways to deceive users, and actively use social engineering techniques to spread their malware. This case demonstrates that such threats can be found even on legitimate sites.”

Indeed. Although the popular perception is that MacOS is much less prone to malware threats, as Shlayer demonstrates, it is by no means immune.

Chris Forte

Chris Forte, President and CEO of Olmec Systems, has been in the MSP workspace for the past 25 years. Chris earned his Master’s Degree from West Virginia University, graduating Magna Cum Laude. He was a past member of the Entrepreneurs’ Organization, a current member of the New Jersey Power Partners and Executive Association of New Jersey, where he has previously served on its board of directors. In his spare time, Chris enjoys traveling with his family. He also admits to being a struggling golfer and avid watcher of college football and basketball. He currently lives in Boonton Township, NJ with his wife, two daughters, son, and black lab Luna.