{"id":90087,"date":"2025-02-15T17:37:27","date_gmt":"2025-02-15T17:37:27","guid":{"rendered":"https:\/\/peraltafinancing.com\/apple-2\/intego-discovers-undetected-osx-adload-decompiled-python-adware\/"},"modified":"2025-02-15T17:37:27","modified_gmt":"2025-02-15T17:37:27","slug":"intego-discovers-undetected-osx-adload-decompiled-python-adware","status":"publish","type":"post","link":"https:\/\/fivemor.com\/?p=90087","title":{"rendered":"Intego discovers undetected OSX\/Adload decompiled Python adware"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"post-103092\">\n<p class=\"cats\"><a href=\"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/\">Malware<\/a><\/p>\n<header>\n<p class=\"about-post\">\n          Posted on<br \/>\n          <time itemprop=\"datePublished\" datetime=\"2025-02-13\">February 13th, 2025<\/time> by<\/p>\n<p>          <span itemprop=\"author\"><br \/>\n            <a href=\"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/\" title=\"Posts by Joshua Long\" class=\"author url fn\" rel=\"author\">Joshua Long<\/a>          <\/span><\/p>\n<p>          <img decoding=\"async\" alt=\"\" src=\"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=18&amp;d=mm&amp;r=g\" srcset=\"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=36&amp;d=mm&amp;r=g 2x\" class=\"avatar avatar-18 photo\" height=\"18\" width=\"18\" loading=\"lazy\"\/>        <\/p>\n<\/header>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-103111 size-full\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2025\/02\/Mac-macOS-OSX-malware-on-iMac-ghostly-figure-with-python-600x350-1.jpg\" alt=\"Mac malware on an iMac with a ghostly figure and a python, representing OSX\/Adload adware\" width=\"600\" height=\"350\"\/><\/p>\n<p>For the past couple years, there has been a plethora of discussion around <a href=\"https:\/\/www.intego.com\/mac-security-blog\/topic\/stealer-malware\/\">stealer malware that infects Macs<\/a>. But other malware families, and categories of malware including potentially unwanted apps (PUA), remain common on Macs, too. Take, for example, the <strong>OSX\/Adload<\/strong> adware.<\/p>\n<p>We\u2019ve been discussing Adload on The Mac Security Blog for close to a decade, and it still hasn\u2019t gone away. Over the past week, our researchers have been taking another look at some recent Adload samples. Here\u2019s what we\u2019ve discovered.<\/p>\n<p><em>In this article:<\/em><\/p>\n<h3>What\u2019s new with OSX\/Adload?<\/h3>\n<p>Historically, Adload adware has been distributed via Trojan horses. For example, it used to <a href=\"https:\/\/www.intego.com\/mac-security-blog\/osx-adload-mac-malware-apple-missed-for-many-months\/\">masquerade as Flash Player installers<\/a>. Later, <a href=\"https:\/\/www.intego.com\/mac-security-blog\/highlights-of-recent-mac-malware-osx-wizardupdate-and-osx-bundlore\/\">UpdateAgent and its successor WizardAgent<\/a> distributed Adload as an additional payload. (See <a href=\"https:\/\/www.intego.com\/mac-security-blog\/?s=adload\">all articles mentioning Adload<\/a>.)<\/p>\n<p>While examining recent variants of OSX\/Adload, we observed that most compiled Mach-O (native Mac executable app) files typically have a detection rate of roughly between one-third to one-half of the antivirus engines on VirusTotal, a multi-engine file scanning site. This is a fairly common detection rate for Mac malware in general. Recent Adload samples are typically self-signed with an ad-hoc signature.<\/p>\n<p>But when assessing Adload\u2019s decompiled Python code, we noticed that <strong>none of the 60+ engines on VirusTotal detected the decompiled Adload Python sample<\/strong> (see the <code>6eb4433f\u2026<\/code> file in the <a href=\"#iocs\">IOCs section<\/a> below). To be clear, that doesn\u2019t necessarily mean that <em>all<\/em> other antivirus products, when actively running on end-user systems, won\u2019t detect the malicious code upon execution; but it does imply that, at least as configured per vendor requests, VirusTotal\u2019s implementation of those engines doesn\u2019t detect the static file.<\/p>\n<p>Furthermore, <strong>only one of the 96 domain reputation tools that VirusTotal uses<\/strong> detects the infection vector site\u2019s domain (<code>m.advancedsprint[.]com<\/code>)\u2014both the subdomain and its parent domain\u2014as malicious.<\/p>\n<p>This suggests that, with little effort from the adware\u2019s developers or distributors, OSX\/Adload may be able to infect many Macs\u2014potentially even if they have certain popular third-party antivirus software installed.<\/p>\n<p>That underscores the need for users to remain vigilant when downloading apps online; even <a href=\"https:\/\/www.intego.com\/mac-security-blog\/cuckoo-returns-mac-malware-spreads-via-legit-looking-google-ads\/\">clicking on links in Google results often leads to malware<\/a>. Using a trusted, Mac-focused anti-malware suite\u2014like Intego\u2019s Mac Premium Bundle, which includes VirusBarrier\u2014is also an essential part of keeping your Mac safe from harmful files and potentially dangerous software.<a name=\"staysafe\"\/><\/p>\n<h3>How can I keep my Mac safe from Adload and other adware or malware?<\/h3>\n<p>If you use Intego VirusBarrier, you\u2019re already protected from this adware. Intego detects these samples as <strong>OSX\/Adload.ext<\/strong> and <strong>Python\/Adload<\/strong>.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignright size-medium wp-image-54214\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/06\/X9-Mac-Antivirus-Launch-300x150.png\" alt=\"Intego X9 software boxes\" width=\"200\" height=\"100\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/06\/X9-Mac-Antivirus-Launch-300x150.png 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/06\/X9-Mac-Antivirus-Launch-150x75.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/06\/X9-Mac-Antivirus-Launch.png 600w\" sizes=\"auto, (max-width: 200px) 100vw, 200px\"\/>Intego VirusBarrier X9, included with <strong><a href=\"https:\/\/offer.intego.com\/BlogMACAV_lbmxlkchf\">Intego\u2019s Mac Premium Bundle X9<\/a><\/strong>, is a powerful solution designed to protect against, detect, and eliminate Mac malware.<\/p>\n<p>If you believe your Mac may be infected, or to prevent future infections, it\u2019s best to use antivirus software from a trusted Mac developer. VirusBarrier is award-winning antivirus software, designed by Mac security experts, that includes <a href=\"https:\/\/www.intego.com\/mac-security-blog\/why-your-antivirus-needs-real-time-scanning\/\">real-time protection<\/a>. It runs natively on both Intel- and Apple silicon-based Macs, and it\u2019s compatible with Apple\u2019s current Mac operating system, macOS Sequoia.<\/p>\n<p>One of VirusBarrier\u2019s unique features is that it can <a href=\"https:\/\/support.intego.com\/hc\/en-us\/articles\/207114798-VirusBarrier-X9-How-to-Scan-iPhone-iPad-and-iPod-Touch\">scan for malicious files on an iPhone, iPad, or iPod touch<\/a> in user-accessible areas of the device. To get started, just attach your iOS or iPadOS device to your Mac via a USB cable and open VirusBarrier.<\/p>\n<p>If you use a Windows PC, <a href=\"https:\/\/www.intego.com\/lp\/route-podcast-intego\/?channel=Podcast_Intego&amp;lpx=buy\"><strong>Intego Antivirus for Windows<\/strong><\/a> can keep your computer protected from malware.<a name=\"iocs\"\/><\/p>\n<h3>Indicators of compromise (IOCs)<\/h3>\n<p>Following are SHA-256 hashes of adware samples related to this OSX\/Adload campaign:<\/p>\n<pre>6eb4433f1eac5a0c018d5c7299b0f1bef08e2c1620d2d5588335a06560be51fc*&#13;\nc5a87badff4431f4df2461fe8137e7d705432e122ed4119c9d9bd5850e87ad39*&#13;\n986fd59d79727ee5f9144fc49ba5e680f7211fd2c555f9e05a0d90b988effa2f\u00b0&#13;\n0455b08439cd4d4283865f3120000338d9920aa95e88448dcd3b493cc0720b10&#13;\n11f0074ed041d32a56a5599ecb924f4ad87fd3b5c38be799aaa9b8944d6f5656&#13;\n134f9d27cf66bc7fde695e5a213fc13fbc327d1f4e977a517b24ef5459d15c9c&#13;\n15c2270a2261d76d86931853850d2d37d69fdd98cf6a3426a325f5e8eb98478c&#13;\n2fda25afec552d39a44764956ae96cf445bfcbd489791cde67dbb4b98f960522&#13;\n364a8eb56a6f85c958ff84ebae61832453929b4aa12b7a75ea2e35301dfd502d&#13;\n40ecfe9ebdb0156ebe1080ffdcba74c45f8e991da20ad887d5b65fe2b5168cdf&#13;\n46a79a9200fb6dd802191d4bfbd98142d13e7edae467cdab72a46d1a3d90e79a&#13;\n50e9747da2ef7454c6f9a833a5cc7363f9e34a12650c1eda819d71bc3ed63f4a&#13;\n51c8d6d866454308c08d602683461dca6930be6dda1e3aabb08e69cc077043d3&#13;\n5ce77544e39cffbe8963e11ebad66c20ebb52beb122471ba60837b4f27dae90f&#13;\n6954fcfd89c531c4893cb8c738b61629f5cb4b621f3f1a8c91df8eaeabc49c30&#13;\n6edfdbfc33e3f0f551052530284c1dde3a8ee3d04ce2ce7b3f75f80ae7c92100&#13;\n79b8e4d59087d94a5bab759c3d86d08b0310a468fa11e2d087500f6f4434300f&#13;\n7b15cc6844ad0381ad84604a818b2ce6c77c44018657e8703d050f2c252213e3&#13;\n7e177745bf37e7dd3e475e448e8c040c2592ac28bb4e5a0ed9cb7feec965d244&#13;\n893085f25b6629070780e5bff9cd53eb7b3c373f732791dee5cf75fa2fd791a8&#13;\na3082b85401386229b0bdd621e3b3978883802b47e0fa8b0923f9778d088e622&#13;\na35368ff999259bc3d795ed1647952989d943ca4317c836a648edf62259ba7e7&#13;\nafdd2d7036e388273e05a60280315d18e1ea630e048529da7320a83a84e545e9&#13;\nb356ce8cc620d183032a38b3a532c79afc8067101fd90c319fd268e9cfd15625&#13;\nbcb4684cf651a197b77f022df50fd9016c52d42adb794701a05305411c998a46&#13;\ncfa4b3b3536224cf8da11f5c02ea576014d86f37dd52a531dd59362967a832c3&#13;\nd750d2f68573956325578c23405e7c59951a78aa5cbf1f087a15e7c0399e79d4&#13;\nddca87fea7e24f7adbe3614de48d371ac28c12bd02b592e6435c395ecacaf821&#13;\ne1afa4dbad6e9f131986240d9d96d1b4d24e021433711f81398293973e05adf6&#13;\n&#13;\n*first detected by Intego; decompiled Python adware&#13;\n\u00b0still only 2\/60 detection rate on VirusTotal<\/pre>\n<p>This adware campaign has leveraged the following domain as an infection vector:<\/p>\n<pre>m.advancedsprint[.]com&#13;\n<\/pre>\n<p>Network administrators can check logs to try to identify whether any computers may have attempted to contact the subdomain above, or its parent domain, which could indicate a possible infection.<a name=\"other-names\"\/><\/p>\n<h3>Do security vendors detect this by any other names?<\/h3>\n<p>Other antivirus vendors\u2019 names for this Adload adware may include variations similar to the following:<\/p>\n<p><span style=\"font-size: small;\">A Variant Of OSX\/TrojanDownloader.Adload.AE, AdLoad (PUA), Adloadr (PUA), Adware:MacOS\/Adload.D!MTB, Adware:MacOS\/Multiverze, Adware.ADWARE\/AVA.Agent.rhafu, Adware.ADWARE\/OSX.AVI.Adload.rajvu, Adware.MAC.AdLoad.AQF (B), Adware.MAC.Agent.BG (B), Adware.Mac.Cimpli.10, Adware.OSX.Adload.2!c, Adware.OSX.Agent.2!c, Adware.OSX.Cimpli.2!c, Adware\/Adload!OSX, ADWARE\/AVA.Agent.rhafu, Adware\/Cimpli!OSX, Adware\/OSX.Adload.d, ADWARE\/OSX.AVI.Adload.rajvu, Downloader.AdLoad\/OSX!1.D942 (CLASSIC), Gen:Variant.Adware.MAC.Adload.15 (B), Gen:Variant.Adware.MAC.Lador.1 (B), Gen:Variant.Application.MAC.Adload.8 (B), HEUR:Trojan-Downloader.OSX.AdLoad.gen, HEUR:Trojan-Downloader.OSX.Agent.ab, HEUR:Trojan-Downloader.OSX.Lador.a, HEUR:Trojan-Downloader.Python.Agent.af, HEUR:Trojan-Dropper.OSX.Agent.s, Linux.Siggen.5031, Mac.DownLoad.11, Mac.Trojan.AdLoad.4, Macho.adware.adload, Macho.downloader.adload, Macho.trojan.adload, Macho.unknown.adload, MacOffers, macOS:Adload-AM [Trj], MacOS:Adload-AX [Adw], MacOS:Adload-CV [Drp], MacOS:Agent-AHI [Trj], MacOS:Agent-MX [Trj], MacOS:Agent-PP [Adw], MacOS:Downloader-BS [Drp], MacOS\/Adload.A.gen!Camelot, MacOS\/Agent.A.gen!Camelot, MacOS\/Agent.B.gen!Camelot, Malware.OSX\/Adload.jleie, Malware.OSX\/Agent.ipwvv, Malware.OSX\/AVI.Adload.avslq, Malware.OSX\/AVI.Agent.gczrk, Malware.OSX\/AVI.Downloader.beswh, Malware.OSX\/Dldr.Adload.ergvp, Malware.OSX\/GM.Adload.OC, Malware.OSX\/GM.Agent.TR, Malware.OSX\/GM.Downloader.TM, MaxOfferDeal, Mughthesec (PUA), Not-a-virus:HEUR:AdWare.OSX.Agent.al, OSX.AdLoad!g1, Osx.Adware.Adload-9885354-2, Osx.AdWare.Agent.Hajl, Osx.Trojan-Downloader.Adload.Anhl, Osx.Trojan-Downloader.Agent.Hjgl, Osx.Trojan-Downloader.Lador.Wimw, Osx.Trojan.Adload.Fflw, Osx.Trojan.Agent.Qwhl, Osx.Trojan.Dldr.Bujl, Osx.Trojan.Gm.Rqil, OSX\/Adload.AX!tr.dldr, OSX\/Agent.BQ!tr, OSX\/Dldr.Adload.pgzct, OSX\/Dwnldr-AASO, OSX\/TrojanDownloader.Adload.AK, Password-Stealer ( 0040f4f11 ), Python:Downloader-AJ [Drp], RDN\/Generic.osx, Static AI \u2013 Malicious Mach-O, Static AI \u2013 Suspicious Mach-O, Trojan-Downloader.OSX.Adload, Trojan-Downloader.OSX.Agent.ad, Trojan:MacOS\/Lador.B!MTB, Trojan:MacOS\/Multiverze, Trojan.Adware.MAC.Adload.22, Trojan.Adware.MAC.Lador.1, Trojan.Application.MAC.Adload.8, Trojan.MAC.Adload.AM (B), Trojan.OSX.Adload.4!c, Trojan.OSX.Agent.4!c, Trojan.OSX.Lador.a!c, Trojan[downloader]:MacOS\/Adload.AH, TrojanDownloader:MacOS\/Adload.B!MTB, TrojanDownloader:MacOS\/SAgnt.C!MTB, TrojanDropper:MacOS\/Lador.K!MTB, Unix.Malware.Lador-9884300-0, Unix.Malware.Macos-9882334-0, Win32.Trojan-Downloader.Agent.Edhl<\/span><a name=\"learnmore\"\/><\/p>\n<h3>How can I learn more?<\/h3>\n<p>Be sure to also check out our <a href=\"https:\/\/www.intego.com\/mac-security-blog\/the-mac-and-iphone-malware-of-2024-and-what-to-expect-in-2025\/#forecast\">2025 Apple malware forecast<\/a> and our previous <a href=\"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/\">Mac malware articles<\/a> from 2025 and earlier.<\/p>\n<p><a href=\"https:\/\/podcast.intego.com\/\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"alignleft\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/04\/intego-podcast-artwork-400.jpg\" alt=\"\" width=\"80\"\/><\/a>Each week on the <a href=\"https:\/\/podcast.intego.com\/\" target=\"_blank\" rel=\"noopener\"><strong>Intego Mac Podcast<\/strong><\/a>, Intego\u2019s Mac security experts discuss the latest Apple news, including security and privacy stories, and offer practical advice on getting the most out of your Apple devices. Be sure to <a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" rel=\"noopener\"><strong>follow the podcast<\/strong><\/a> to make sure you don\u2019t miss any episodes.<\/p>\n<p>You can also subscribe to our <a href=\"https:\/\/www.intego.com\/mac-security-blog\/mac-security-newsletter\/\"><strong>e-mail newsletter<\/strong><\/a> and keep an eye here on <a href=\"https:\/\/www.intego.com\/mac-security-blog\"><strong>The Mac Security Blog<\/strong><\/a> for the latest Apple security and privacy news. And don\u2019t forget to follow Intego on your favorite social media channels: <a href=\"https:\/\/x.com\/IntegoSecurity\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on \ud835\udd4f\/Twitter\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/X-Twitter-logo-icon-225.gif\" alt=\"Follow Intego on X\/Twitter\" width=\"16\"\/><\/a>\u00a0<a href=\"https:\/\/www.facebook.com\/Intego\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on Facebook\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/Facebook-logo-icon-225.gif\" alt=\"Follow Intego on Facebook\" width=\"16\"\/><\/a>\u00a0<a href=\"https:\/\/www.youtube.com\/user\/IntegoVideo?sub_confirmation=1\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" style=\"border-width: 1px; border-style: solid; border-color: rgba(0, 0, 0, 0.2); border-radius: 8px;\" title=\"Follow Intego on YouTube\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/YouTube-logo-icon-225.png\" alt=\"Follow Intego on YouTube\" width=\"16\"\/><\/a>\u00a0<a href=\"https:\/\/www.pinterest.com\/intego\/\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" style=\"border-width: 1px; border-style: solid; border-color: rgba(0, 0, 0, 0.2); border-radius: 8px;\" title=\"Follow Intego on Pinterest\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/Pinterest-logo-icon-225.png\" alt=\"Follow Intego on Pinterest\" width=\"16\"\/><\/a>\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/intego\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on LinkedIn\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/LinkedIn-logo-icon-225.gif\" alt=\"Follow Intego on LinkedIn\" width=\"16\"\/><\/a>\u00a0<a href=\"https:\/\/www.instagram.com\/intego_security\/\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on Instagram\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/Instagram-logo-icon-225.gif\" alt=\"Follow Intego on Instagram\" width=\"16\"\/><\/a>\u00a0<a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow the Intego Mac Podcast on Apple Podcasts\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile.png\" alt=\"Follow the Intego Mac Podcast on Apple Podcasts\" width=\"16\"\/><\/a><\/p>\n<p>\t\t\t\t\t\t\t<img decoding=\"async\" alt=\"\" src=\"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=60&amp;d=mm&amp;r=g\" srcset=\"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=120&amp;d=mm&amp;r=g 2x\" class=\"avatar avatar-60 photo\" height=\"60\" width=\"60\" loading=\"lazy\"\/>\t\t\t\t<\/p>\n<h3>About Joshua Long<\/h3>\n<p>\t\t\t\t<b>Joshua Long<\/b> (<a href=\"https:\/\/twitter.com\/theJoshMeister\">@theJoshMeister<\/a>), Intego&#8217;s Chief Security Analyst, is a renowned security researcher and writer, and an award-winning public speaker. Josh has a master&#8217;s degree in IT concentrating in Internet Security and has taken doctorate-level coursework in Information Security. Apple has publicly acknowledged Josh for discovering an Apple\u00a0ID authentication vulnerability. Josh has conducted cybersecurity research for more than 25 years, which is often featured by major news outlets worldwide. Look for more of Josh&#8217;s articles at <a href=\"https:\/\/security.thejoshmeister.com\">security.thejoshmeister.com<\/a> and follow him on <a href=\"https:\/\/x.com\/theJoshMeister\">X\/Twitter<\/a>, <a href=\"https:\/\/www.linkedin.com\/in\/theJoshMeister\">LinkedIn<\/a>, and <a href=\"https:\/\/infosec.exchange\/@theJoshMeister\">Mastodon<\/a>.\t\t\t\t\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/\"><br \/>\n\t\t\t\t\t\tView all posts by Joshua Long \u2192\t\t\t\t\t<\/a><\/p>\n<footer>\n\t\t\t\tThis entry was posted in <a href=\"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/\" rel=\"category tag\">Malware<\/a> and tagged <a href=\"https:\/\/www.intego.com\/mac-security-blog\/topic\/mac-malware\/\" rel=\"tag\">Malware<\/a>, <a href=\"https:\/\/www.intego.com\/mac-security-blog\/topic\/osx-adload\/\" rel=\"tag\">OSX\/Adload<\/a>. Bookmark the <a href=\"https:\/\/www.intego.com\/mac-security-blog\/intego-discovers-undetected-osx-adload-decompiled-python-adware\/\" title=\"Permalink to Intego discovers undetected OSX\/Adload decompiled Python adware\" rel=\"bookmark\">permalink<\/a>.\t\t\t\t\t\t\t<\/footer>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><script async src=\"\/\/www.instagram.com\/embed.js\"><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Malware Posted on February 13th, 2025 by Joshua Long For the past couple years, there has been a plethora of discussion around stealer malware that infects Macs. But other malware families, and categories of malware including potentially unwanted apps (PUA), remain common on Macs, too. Take, for example, the OSX\/Adload adware. We\u2019ve been discussing Adload [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":90088,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11768],"tags":[40630,43660,32892,27482,22198,43657,43659,21302,43658],"dealstore":[],"offerexpiration":[],"class_list":["post-90087","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-apple-2","tag-adware","tag-decompiled","tag-discovers","tag-intego","tag-malware","tag-osx-adload","tag-osxadload","tag-python","tag-undetected"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Intego discovers undetected OSX\/Adload decompiled Python adware - Som2ny Network<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/fivemor.com\/?p=90087\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Intego discovers undetected OSX\/Adload decompiled Python adware - Som2ny Network\" \/>\n<meta property=\"og:description\" content=\"Malware Posted on February 13th, 2025 by Joshua Long For the past couple years, there has been a plethora of discussion around stealer malware that infects Macs. But other malware families, and categories of malware including potentially unwanted apps (PUA), remain common on Macs, too. Take, for example, the OSX\/Adload adware. We\u2019ve been discussing Adload [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/fivemor.com\/?p=90087\" \/>\n<meta property=\"og:site_name\" content=\"Som2ny Network\" \/>\n<meta property=\"article:published_time\" content=\"2025-02-15T17:37:27+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/Mac-macOS-OSX-malware-on-iMac-ghostly-figure-with-python-400x260-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"260\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/fivemor.com\/?p=90087#article\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/?p=90087\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\"},\"headline\":\"Intego discovers undetected OSX\/Adload decompiled Python adware\",\"datePublished\":\"2025-02-15T17:37:27+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=90087\"},\"wordCount\":1288,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=90087#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/Mac-macOS-OSX-malware-on-iMac-ghostly-figure-with-python-400x260-1.jpg\",\"keywords\":[\"adware\",\"decompiled\",\"Discovers\",\"Intego\",\"Malware\",\"OSX\/Adload\",\"OSXAdload\",\"Python\",\"undetected\"],\"articleSection\":[\"Apple\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/fivemor.com\/?p=90087#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/fivemor.com\/?p=90087\",\"url\":\"https:\/\/fivemor.com\/?p=90087\",\"name\":\"Intego discovers undetected OSX\/Adload decompiled Python adware - Som2ny Network\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=90087#primaryimage\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=90087#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/Mac-macOS-OSX-malware-on-iMac-ghostly-figure-with-python-400x260-1.jpg\",\"datePublished\":\"2025-02-15T17:37:27+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/fivemor.com\/?p=90087#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/fivemor.com\/?p=90087\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/?p=90087#primaryimage\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/Mac-macOS-OSX-malware-on-iMac-ghostly-figure-with-python-400x260-1.jpg\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/Mac-macOS-OSX-malware-on-iMac-ghostly-figure-with-python-400x260-1.jpg\",\"width\":400,\"height\":260},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/fivemor.com\/?p=90087#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/fivemor.com\/?bp_activities=1\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Intego discovers undetected OSX\/Adload decompiled Python adware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/fivemor.com\/#website\",\"url\":\"https:\/\/fivemor.com\/\",\"name\":\"Som2ny Network\",\"description\":\"Daily Deals\",\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/fivemor.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/fivemor.com\/#organization\",\"name\":\"Som2ny Network\",\"url\":\"https:\/\/fivemor.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"width\":300,\"height\":86,\"caption\":\"Som2ny Network\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/fivemor.com\"],\"url\":\"https:\/\/fivemor.com\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Intego discovers undetected OSX\/Adload decompiled Python adware - Som2ny Network","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/fivemor.com\/?p=90087","og_locale":"en_US","og_type":"article","og_title":"Intego discovers undetected OSX\/Adload decompiled Python adware - Som2ny Network","og_description":"Malware Posted on February 13th, 2025 by Joshua Long For the past couple years, there has been a plethora of discussion around stealer malware that infects Macs. But other malware families, and categories of malware including potentially unwanted apps (PUA), remain common on Macs, too. Take, for example, the OSX\/Adload adware. We\u2019ve been discussing Adload [&hellip;]","og_url":"https:\/\/fivemor.com\/?p=90087","og_site_name":"Som2ny Network","article_published_time":"2025-02-15T17:37:27+00:00","og_image":[{"width":400,"height":260,"url":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/Mac-macOS-OSX-malware-on-iMac-ghostly-figure-with-python-400x260-1.jpg","type":"image\/jpeg"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/fivemor.com\/?p=90087#article","isPartOf":{"@id":"https:\/\/fivemor.com\/?p=90087"},"author":{"name":"admin","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371"},"headline":"Intego discovers undetected OSX\/Adload decompiled Python adware","datePublished":"2025-02-15T17:37:27+00:00","mainEntityOfPage":{"@id":"https:\/\/fivemor.com\/?p=90087"},"wordCount":1288,"commentCount":0,"publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"image":{"@id":"https:\/\/fivemor.com\/?p=90087#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/Mac-macOS-OSX-malware-on-iMac-ghostly-figure-with-python-400x260-1.jpg","keywords":["adware","decompiled","Discovers","Intego","Malware","OSX\/Adload","OSXAdload","Python","undetected"],"articleSection":["Apple"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/fivemor.com\/?p=90087#respond"]}]},{"@type":"WebPage","@id":"https:\/\/fivemor.com\/?p=90087","url":"https:\/\/fivemor.com\/?p=90087","name":"Intego discovers undetected OSX\/Adload decompiled Python adware - Som2ny Network","isPartOf":{"@id":"https:\/\/fivemor.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/fivemor.com\/?p=90087#primaryimage"},"image":{"@id":"https:\/\/fivemor.com\/?p=90087#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/Mac-macOS-OSX-malware-on-iMac-ghostly-figure-with-python-400x260-1.jpg","datePublished":"2025-02-15T17:37:27+00:00","breadcrumb":{"@id":"https:\/\/fivemor.com\/?p=90087#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/fivemor.com\/?p=90087"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/?p=90087#primaryimage","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/Mac-macOS-OSX-malware-on-iMac-ghostly-figure-with-python-400x260-1.jpg","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/Mac-macOS-OSX-malware-on-iMac-ghostly-figure-with-python-400x260-1.jpg","width":400,"height":260},{"@type":"BreadcrumbList","@id":"https:\/\/fivemor.com\/?p=90087#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/fivemor.com\/?bp_activities=1"},{"@type":"ListItem","position":2,"name":"Intego discovers undetected OSX\/Adload decompiled Python adware"}]},{"@type":"WebSite","@id":"https:\/\/fivemor.com\/#website","url":"https:\/\/fivemor.com\/","name":"Som2ny Network","description":"Daily Deals","publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/fivemor.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/fivemor.com\/#organization","name":"Som2ny Network","url":"https:\/\/fivemor.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","width":300,"height":86,"caption":"Som2ny Network"},"image":{"@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","caption":"admin"},"sameAs":["https:\/\/fivemor.com"],"url":"https:\/\/fivemor.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/90087","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=90087"}],"version-history":[{"count":0,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/90087\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/media\/90088"}],"wp:attachment":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=90087"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=90087"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=90087"},{"taxonomy":"dealstore","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdealstore&post=90087"},{"taxonomy":"offerexpiration","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fofferexpiration&post=90087"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}