
A trojan that attempts to trick macOS into downloading malware remains the most common malware Mac users encounter.
The malware, called Shlayer, first appeared in early 2018 and is primarily used to install malware on users' systems, with the aim of generating revenue from pop-up advertisements and links that repeatedly appear in the victim.
Two years after its release, Kaspersky Labs researchers say it has affected about 1 in 10 Mac users, making it the most common malware for macOS.
Shlayer's primary distribution method is through Flash updates that have infiltrated thousands of websites.
It is often found on websites that allow users to illegally watch TV shows and sporting events – and they often ask the user to download a fake Flashin order to watch their selected content. This allows Shlayer to spread.
The malware is also distributed via legitimate websites, with links that download the malware to Apple. Researchers have uncovered 700 different domains linking to a variety of legitimate websites.
macOS users around the world have been affected by this malware, but most have been detected in the US, Germany, France , and the UK. Meanwhile, the trojan shows no signs of slowing down, while still generating revenue for its operators.
Furthermore, it becomes apparent that the macOS operating system is not as invulnerable as the company claims.
“The macOS platform is a good source of income for cybercriminals who are constantly looking for new ways to deceive users and use social engineering techniques to spread their malware,” said Anton Ivanov, security analyst at Kaspersky Lab.
To avoid falling victim to Shlayer and other malware, researchers recommend that users only install software and updates from trusted sources.
