Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Feb 22, 2022 | Updated Apr 18, 2022

TrojanDownloader:MacOS/Shlayer.A!xp

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

Microsoft Defender Antivirus detects and removes this threat.

This threat is a MacOS trojan which masquerades as a legitimate Adobe Flash Player update. It contains a shell script that is designed to install additional malware such as Bundlore, Pirrit, Geonie, and other unwanted applications and could provide backdoor capabilities to attackers.

Microsoft Defender Antivirus automatically removes threats as they are detected. If you have cloud-delivered protection, your device gets the latest defenses against new and unknown threats. If you don't have this feature enabled, update your antimalware definitions and run a full scan to remove this threat.

To help reduce the impact of this threat, you can:

  1. Check whether software has recently been downloaded or installed from unverified sources.
  2. Review the file and the process responsible for the activity.
  3. Review the device timeline for any suspicious activities that have occurred around the time of the alert. Identify and review other affected devices.
  4. If confirmed malicious, contain and mitigate the breach. Stop suspicious processes, isolate affected devices, decommission compromised accounts or reset their passwords, block IP addresses and URLs, and install security updates.

You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.

Follow us