Skip to content
Log In
Request Trial

1 Million Macs Exposed to Malvertising Scam

By | Published

A malvertising campaign has been targeting Macs since at least mid-January, with at least a million machines exposed, security firm Confiant said in a blog posting this week.

The malicious ads lure users into updating their Adobe Flash players—but that update is really a downloader called Shlayer that opens up the Mac to even more malware. To evade malware screeners, the ads first load normally, but then draw in malicious content from a Firebase, a Google-hosted online data repository designed for mobile-app makers.

Unfortunately, not that many Mac antivirus brands recognized the Shlayer malware signature yet. As of this writing on Thursday afternoon (March 21), the corporate siblings Avast and AVG did, as did Avira and Bitdefender and their licensees (Emsisoft, F-Secure, GData and Qihoo 360), plus a couple of others. But dozens of other antimalware engines listed on the VirusTotal page for Shlayer's signature let the malware slip by.

Our advice would be to ignore any pop-up windows suggesting that you update Flash Player, especially if you're using Safari, which Shlayer seems to prefer. (Go to the official Flash update page at instead.) Alternately, you could use an ad blocker.

Read Complete Article:,news-29700.html

Share this story

Subscribe to our newsletter to stay up to date on the latest trends and emerging threats.

Take Us For A Spin

Request a trial and see how it feels to have Confiant on your side.

Request Trial