Also known as: OSX.Bundlore
Executive Summary
Bundlore is a macOS adware that evolved into a multi‑capability backdoor, persisting stealthily while offering remote command execution and payload delivery. Its ability to masquerade as legitimate software and exploit system APIs makes it difficult to detect with standard AV solutions. Consequently, it poses a significant risk for data exfiltration and persistent intrusion on infected Macs.
Enhanced Description
Bundlore is a long‑standing macOS adware family that has been in circulation since at least 2015. While it presents itself primarily as an advertising platform, security analyses have uncovered a suite of capabilities that align more closely with traditional backdoor malware. These features include stealth persistence mechanisms, remote configuration capabilities, and the ability to download additional payloads from command-and-control servers. The malware typically installs under hidden application bundles or system extensions, masking its presence from casual users and basic antivirus tools. Once active, Bundlore communicates over persistent network channels and can request new malware modules, effectively turning infected machines into mobile “zombies”. This dual nature—advertising on one side, remote control and potential data exfiltration on the other—raises serious concern for enterprise and personal macOS users. Security teams have observed Bundlore’s exploitation of system privileges to circumvent sandboxing restrictions. By leveraging legitimate Apple APIs, it can inject code into trusted processes and suppress security alerts, further extending its lifespan in compromised environments.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The available information confirms Bundlore’s classification as macOS adware with backdoor features. While core capabilities are documented, details on specific command‑and‑control protocols, persistence vectors, or the full malware family lineage remain incomplete due to limited open-source reports.
Bundlore is adware written for macOS that has been in use since at least 2015. Though categorized as adware, Bundlore has many features associated with more traditional backdoors.(Citation: MacKeeper Bundlore Apr 2019)