Netskope Threat Labs

Bundlore

AV

Bundlore (a.k.a. SurfBuyer) is an adware installer for macOS that has circulated since 2015 in many forms, including Flash player installers, hidden scripts, and browser plugins. Its installers bundle unwanted advertising software with popular free applications and modify browser settings to redirect searches and inject advertisements. The family continually refreshes its installers to slip past Apple's security checks, which has kept it among the most persistent macOS adware threats.

First seen
January 2022
Last seen
October 2026

23 techniques across 9 tactics.

TA0001 Initial Access

TA0002 Execution

TA0003 Persistence

TA0005 Stealth

  • T1027Obfuscated Files or Information
  • T1036Masquerading
    • T1036.005Match Legitimate Resource Name or Location
  • T1140Deobfuscate/Decode Files or Information
  • T1564Hide Artifacts

TA0007 Discovery

  • T1057Process Discovery
  • T1082System Information Discovery
  • T1518Software Discovery

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1048Exfiltration Over Alternative Protocol

TA0112 Defense Impairment

  • T1222File and Directory Permissions Modification
  • T1685Disable or Modify Tools
Alert Name
Adware.MAC.Bundlore.27539
Adware.MAC.Bundlore.DFR
Adware.MAC.Bundlore.DGF
Adware.MAC.Bundlore.DGJ
Adware.MAC.Bundlore.DGL
Adware.MAC.Bundlore.DGS
Adware.MAC.Bundlore.DHH
Adware.MAC.Bundlore.DHN
Adware.MAC.Bundlore.DHQ
Adware.MAC.Bundlore.DHS