VORANT. Threat Intelligence Sign in Get the full feed

Pirrit adware ships native M1 binary

low threat

Researchers found GoSearch22, a Pirrit adware variant, compiled with native Apple Silicon (arm64) code, likely the first M1-native macOS malware.

Objective-See researcher Patrick Wardle, while porting his own tools to run natively on Apple's M1 chips, hunted VirusTotal for malicious universal Mach-O binaries containing arm64 code and discovered GoSearch22, a macOS application signed with a (since revoked) Apple developer ID. Analysis of the app bundle confirmed it is a variant of the well-known Pirrit adware family, bundling a Safari extension that injects ads and can collect browsing data, IPs, search queries, and geolocation. The sample includes anti-analysis logic such as ptrace-based anti-debugging (PT_DENY_ATTACH) and multiple checks for virtual-machine artifacts to hinder sandboxed analysis.

The significance of the find is less about Pirrit's adware behavior—which is well documented—and more about the precedent it sets: malware authors are now compiling multi-architecture binaries to gain native compatibility with Apple Silicon, following the same porting incentives as legitimate developers. Wardle's testing showed that splitting the binary into separate x86_64 and arm64 versions and rescanning them on VirusTotal produced roughly 15% lower detection rates for the arm64 slice, with some AV engines failing to flag the arm64 code at all or labeling it inconsistently versus the x86_64 equivalent.

The sample was originally submitted to VirusTotal in December 2020 via an Objective-See tool (likely KnockKnock) after a user's persistence mechanism triggered a flag. There is no indication of large-scale active distribution beyond typical adware bundling/installation vectors, and the finding is primarily a research observation about detection-engineering gaps for Apple Silicon rather than an active large-scale campaign.

Mentioned in this report

Malware GoSearch22Pirrit

Source reporting: https://objective-see.org/blog/blog_0x62.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free