VORANT. Threat Intelligence Sign in Get the full feed

Adware Doctor App Exfiltrates Mac Browser History

medium threat

Adware Doctor, a top-grossing Mac App Store utility, secretly collected users' Safari, Chrome and Firefox history plus system data and uploaded it to remote servers.

Researchers found that Adware Doctor, a paid anti-adware utility that ranked as the #4 top-grossing app and #1 paid utility in the official Mac App Store, was secretly harvesting and exfiltrating sensitive user data. Despite running inside Apple's App Sandbox, the app abused a user-granted file-access entitlement (obtained under the guise of legitimate adware scanning) to read Safari, Chrome and Firefox history databases, App Store search history, a list of downloaded installers, and system/process information. It then zipped this data into a password-protected archive and uploaded it over HTTPS to yelabapp.com infrastructure via an API endpoint named 'checkadware'.

Analysis of the binary revealed the app also circumvented sandbox restrictions on process enumeration (normally blocking /bin/ps) by directly invoking sysctl/KERN_PROC_ALL logic copied from Apple's own sample code, a technique that should not be permitted for sandboxed App Store apps. The app has a documented history of AppleScript abuse, name-squatting on a competitor's brand, and fake reviews, and its developer identity ('Yongming Zhang') could not be substantively verified. Despite being reported to Apple roughly a month prior, the app remained available until public disclosure forced its removal, raising concerns about the effectiveness of Apple's App Store review and vetting process.

The exfiltration endpoint (adscan.yelabapp.com) went offline shortly before publication, though the app's local collection logic remained active and could resume exfiltration if the endpoint were restored. The incident illustrates how App Store review can miss sandbox-bypass techniques and covert data collection even in top-grossing, widely trusted applications.

Mentioned in this report

Threat actors Yongming Zhang
Malware Adware Doctor

Source reporting: https://objective-see.org/blog/blog_0x37.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free