VORANT. Threat Intelligence Sign in Get the full feed

MapperState malware targets Apple M1 Macs

medium threat

Confiant found MapperState, a new ARM-native downloader tied to OSX/Tarmac and Hydromac, delivered via malvertising to notarized Apple M1 Macs.

Confiant researchers discovered a new macOS malware sample, dubbed MapperState, delivered to their honeypot via malvertising through the OSX/Bundlore loader and OSX/Tarmac dropper. Notably, MapperState was compiled for ARM64 and notarized by Apple, making it compatible with the new M1 MacBooks. The malware uses heavy string encryption and anti-analysis tricks—198 duplicated decryption code blocks—to slow reverse engineering, requiring Confiant to emulate the routines with Unicorn Engine and custom IDAPython tooling to extract the encrypted command strings.

Analysis revealed MapperState functions as a Hydromac Root Agent (HM_RA), a simple downloader capable of retrieving and executing further payloads and checking installed AV products, though the C2 server (mapperstate[.]com) returned empty content during investigation, so the final payload was not observed. Confiant traced command naming and functionality overlaps between MapperState, older OSX/Tarmac samples (2019), a related Hydromac Agent sample communicating with a C2 previously tied to the 2017 Mughthesec malware (documented by Patrick Wardle), and public flashcard app entries created by an individual whose OPSEC mistakes exposed personal details and links to a Facebook-ads-renting scheme called "CashWithFB."

The findings suggest a long-running, evolving malvertising-driven malware lineage (Mughthesec → Tarmac → Hydromac/MapperState) targeting macOS users, with a possible but unconfirmed link between the leaker of command details and malvertising affiliate operations. Confiant explicitly declines to make firm individual-level attribution, leaving that to other organizations, while noting the malware is actively evolving to counter analysis tools.

Mentioned in this report

Malware HydromacMapperStateMughthesecOSX/BundloreOSX/Tarmac

Source reporting: https://objective-see.org/blog/blog_0x65.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free