New AdLoad Campaign Focuses on Apple Devices, Macs
Researchers with Sentinel Labs released a new publication on a brand-new malicious campaign targeting Apple devices. The campaign is spreading the known AdLoad malware.
AdLoad is not a new threat. The malware has been known to researchers for a while now, with its first samples being documented as early as 2017. The report published by Sentinel Labs details a staggering 150 newer samples of the AdLoad malware which act acts as a loader for adware and bundleware. The issue is, according to Sentinel Labs researchers, those new samples can slip by the "on-device malware scanner" Apple uses.
The anti-malware security suite used by Apple on Mac computers is called XProtect. After the original reports of AdLoad's existence, Apple did include AdLoad protection in the XProtect platform. However, this only covers some of the iterations and samples of AdLoad, stretching back to around the year 2019.
The new campaign described by Sentinel Labs, however, includes samples that don't trip up Mac defenses. The samples of AdLoad that are being actively used in the malicious campaign in 2021 uses patterns that depend on file extensions, using the extensions .system or .service. Usually, a system infected with the latest version of AdLoad will have both of those show up on it.
Sentinel Labs further explains that the new AdLoad malware uses a fake Player.app file, stored inside a DMG disk image file. A lot of the examined samples even have valid signatures. Apple is always monitoring for newly reported malware and malicious samples that get uploaded to joint-effort services such as VirusTotal usually have their certificates revoked very quickly. Sadly, the bad actors are quick on the uptake as well and new samples with new signatures sprout up just as quickly too.
In its report Sentinel Labs quotes data from security firm Confiant, who confirm that some of the AdLoad samples used in the current campaign have actually been notarized by Apple as well.
While some of the new samples of the AdLoad malware were spotted in late 2020, the majority of the AdLoad attacks took place in the months of July and August in 2021.
Sentinel Labs highlighted the fact that there have been a large number of known adware variants and samples that are still undetected by the Apple on-device scanning service and this may be indication that Macs may need additional security software.