Pirrit adware ships native M1 binary
Researchers found GoSearch22, a Pirrit adware variant, compiled with native Apple Silicon (arm64) code, likely the first M1-native macOS malware.
Objective-See researcher Patrick Wardle, while porting his own tools to run natively on Apple's M1 chips, hunted VirusTotal for malicious universal Mach-O binaries containing arm64 code and discovered GoSearch22, a macOS application signed with a (since revoked) Apple developer ID. Analysis of the app bundle confirmed it is a variant of the well-known Pirrit adware family, bundling a Safari extension that injects ads and can collect browsing data, IPs, search queries, and geolocation. The sample includes anti-analysis logic such as ptrace-based anti-debugging (PT_DENY_ATTACH) and multiple checks for virtual-machine artifacts to hinder sandboxed analysis.
The significance of the find is less about Pirrit's adware behavior—which is well documented—and more about the precedent it sets: malware authors are now compiling multi-architecture binaries to gain native compatibility with Apple Silicon, following the same porting incentives as legitimate developers. Wardle's testing showed that splitting the binary into separate x86_64 and arm64 versions and rescanning them on VirusTotal produced roughly 15% lower detection rates for the arm64 slice, with some AV engines failing to flag the arm64 code at all or labeling it inconsistently versus the x86_64 equivalent.
The sample was originally submitted to VirusTotal in December 2020 via an Objective-See tool (likely KnockKnock) after a user's persistence mechanism triggered a flag. There is no indication of large-scale active distribution beyond typical adware bundling/installation vectors, and the finding is primarily a research observation about detection-engineering gaps for Apple Silicon rather than an active large-scale campaign.
Mentioned in this report
Source reporting: https://objective-see.org/blog/blog_0x62.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free