Adware.Shlayer

ThreatDown is now the name of the Malwarebytes line of business products. References to Malwarebytes below reflect the amazing technology used to first identify the threat.

Short bio

Adware.Shlayer is Malwarebytes’ detection name for a family of adware bundlers that target macOS systems.

Type of infection

Adware.Shlayer use shell scripts to install their adware payload. And they do this only once per installer, probably to hinder analysis. Even when run on a different machine an installer that has already been run will not drop the payload again. Adware.Shlayer are typically distributed in the form of fake Adobe Flash Player installers.

Malicious behavior

Adware.Shlayer, like most adware, is software that displays unwanted advertising on your computer device.

Protection

Malwarebytes for Mac detects and removes Adware.Shlayer.

Home remediation

Malwarebytes for Mac will detect and remove the components of this malware.