# Pirrit adware ships native M1 binary

Published: 2021-02-14 · Severity: low
Canonical: https://vorant.io/reports/a8cca364-2129-5246-b23d-7c8ae3975ef3/pirrit-adware-ships-native-m1-binary

> Researchers found GoSearch22, a Pirrit adware variant, compiled with native Apple Silicon (arm64) code, likely the first M1-native macOS malware.

Objective-See researcher Patrick Wardle, while porting his own tools to run natively on Apple's M1 chips, hunted VirusTotal for malicious universal Mach-O binaries containing arm64 code and discovered GoSearch22, a macOS application signed with a (since revoked) Apple developer ID. Analysis of the app bundle confirmed it is a variant of the well-known Pirrit adware family, bundling a Safari extension that injects ads and can collect browsing data, IPs, search queries, and geolocation. The sample includes anti-analysis logic such as ptrace-based anti-debugging (PT_DENY_ATTACH) and multiple checks for virtual-machine artifacts to hinder sandboxed analysis.

The significance of the find is less about Pirrit's adware behavior—which is well documented—and more about the precedent it sets: malware authors are now compiling multi-architecture binaries to gain native compatibility with Apple Silicon, following the same porting incentives as legitimate developers. Wardle's testing showed that splitting the binary into separate x86_64 and arm64 versions and rescanning them on VirusTotal produced roughly 15% lower detection rates for the arm64 slice, with some AV engines failing to flag the arm64 code at all or labeling it inconsistently versus the x86_64 equivalent.

The sample was originally submitted to VirusTotal in December 2020 via an Objective-See tool (likely KnockKnock) after a user's persistence mechanism triggered a flag. There is no indication of large-scale active distribution beyond typical adware bundling/installation vectors, and the finding is primarily a research observation about detection-engineering gaps for Apple Silicon rather than an active large-scale campaign.

## Mentioned in this report

- Malware: GoSearch22, Pirrit

Source reporting: https://objective-see.org/blog/blog_0x62.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/a8cca364-2129-5246-b23d-7c8ae3975ef3/pirrit-adware-ships-native-m1-binary.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
