Netskope Threat Labs

OSX/Shlayer

ATP Sandbox Adv. HeuristicsAV

OSX/Shlayer (a.k.a. CrossRider) is a trojan and adware family for macOS that spreads through fake software updates and browser extensions to install additional unwanted software. It rose to prominence through fake Flash player update pages on compromised and scam websites, and researchers ranked it among the most common macOS threats for years. Its installers drop adware payloads that hijack search settings and inject advertisements, and its distribution chains have repeatedly survived App Store and browser security improvements.

First seen
January 2022
Last seen
October 2026
CrossRiderCrossriderZShlayer

15 techniques across 7 tactics.

TA0002 Execution

TA0003 Persistence

TA0004 Privilege Escalation

  • T1548Abuse Elevation Control Mechanism

TA0005 Stealth

TA0007 Discovery

  • T1082System Information Discovery
  • T1083File and Directory Discovery

TA0011 Command and Control

  • T1105Ingress Tool Transfer

TA0112 Defense Impairment

Alert Name
Adware.Crossrider.EA
Adware.JS.Crossrider.B
Adware.JS.Crossrider.C
Adware.JS.Crossrider.D
Adware.JS.Crossrider.E
Adware.JS.Crossrider.G
Adware.JS.Crossrider.M
Adware.JS.Crossrider.N
Adware.JS.Crossrider.O
Adware.JS.Crossrider.P