Bundlore is an extremely prevalent adware that targets macOS systems by bundling unwanted applications with legitimate software installers. It often masquerades as popular software updaters and installers, deceiving users into installing additional unwanted programs. Once installed, Bundlore injects advertisements into web browsers, redirects user searches, and collects sensitive browsing data. Bundlore is sometimes dropped by macOS malware Shlayer.
You might observe the following artifacts associated with this threat:
Bundlore is distributed through deceptive means such as:
Bundlore performs the following actions:
Bundlore has continually evolved over time, with variants employing ever-changing techniques to evade detection and removal. Some versions have been observed modifying the sudoers file to remove the password requirement for privilege escalation.
Kandji Endpoint Detection & Response (EDR) automatically removes detected threats when file monitoring is set to Protect.
While the malicious file is removed, it can leave behind artifacts that need to be cleaned manually.
In the future, avoid downloading and installing software from torrent sources or untrusted websites. Ensure that all applications are obtained from official and reputable sources to maintain system integrity and security.