ReaderUpdate Malware Evolves: A Growing Threat to macOS Users

Listen to this Post

Cybersecurity researchers at SentinelOne have issued a warning about the evolution of the ReaderUpdate malware, which is now targeting macOS users in multiple programming languages, including Crystal, Nim, Rust, and Go. Originally detected as a compiled Python binary delivering adware, the malware remained under the radar for years before resurfacing with more sophisticated variants in late 2024.

The latest research highlights five distinct versions of ReaderUpdate, each compiled in a different language, making detection and mitigation more challenging. The malware spreads through infected applications and old infections, maintaining persistence through system-level configurations. Analysts believe it could be part of a larger Pay-Per-Install (PPI) or Malware-as-a-Service (MaaS) scheme, posing a severe threat to macOS security.

This article explores the different variants of ReaderUpdate, their behavior, and the broader implications of this emerging malware campaign.

ReaderUpdate: A Malware Campaign in Five Languages

A Long-Standing Threat with New Variants

ReaderUpdate first appeared in 2020, initially distributing Genieo adware. It was relatively undetected until 2024, when new versions emerged in Crystal, Nim, and Rust. SentinelOne’s latest findings indicate that the malware is now being distributed in five different source languages:

| Language | Size | Example SHA-1 |

|-|||

| Compiled Python | 5.6MB | fe9ca39a8c3261a4a81d3da55c02ef3ee2b8863f |

| Go | 4.5MB | 36ecc371e0ef7ae46f25c137aa0498dfd4ff70b3 |

| Crystal | 1.2MB | 86431ce246b54ec3372f08c7739cd1719715b824 |

| Rust | 400KB | 01e762ef8a10undercodeda639ed62ef93b784268d925a |

| Nim | 166KB | 21a2ec703a68382b23ce9ff03ff62dae07374222 |

How ReaderUpdate Spreads

The malware propagates through multiple channels:

  • Older infections: Systems already compromised may unknowingly spread new variants.
  • Trojanized applications: Malicious versions of software such as “DragonDrop” are used to distribute the malware.
  • Third-party downloads: Users downloading software from unverified sources risk exposure.

All identified versions of ReaderUpdate are compiled for Intel x86 architecture, meaning they require Rosetta 2 to function on Apple Silicon devices.

New Go Variant: A Closer Look

While Crystal, Nim, and Rust variants have been under analysis, SentinelOne is now documenting the Go variant for the first time. Key features of the Go-based ReaderUpdate include:
– System reconnaissance: The malware collects system hardware information to create unique victim IDs.
– Persistence mechanisms: It installs itself in the ~/Library/Application Support/ directory and maintains persistence using .plist files.
– Command and Control (C2) Execution: It receives and executes remote commands from a C2 server.
– Obfuscation techniques: The malware uses string obfuscation and character substitution to evade analysis.

A Stealthy and Dangerous Loader

SentinelOne researchers emphasize that ReaderUpdate is more than just adware. Its ability to remain dormant for extended periods makes it a perfect tool for delivering more dangerous payloads. The malware can be used by cybercriminals to distribute ransomware, spyware, or other malware strains as part of a MaaS or PPI business model.

Even though the Go variant is rarer than others (only nine samples detected so far), its connection to a larger malware infrastructure suggests it may play a crucial role in future cyber threats.

What Undercode Says: Analyzing the ReaderUpdate Malware

The emergence of ReaderUpdate in multiple programming languages highlights a major shift in malware development trends. Traditionally, macOS threats were often seen as less sophisticated compared to Windows-based malware. However, the evolution of this loader suggests that threat actors are investing in platform-agnostic and highly evasive techniques.

Key Observations

1. Diversification of Malware Code

  • By using Crystal, Nim, Rust, and Go, cybercriminals increase the complexity of detection.
  • Security tools need to adapt to detect malware written in less common languages.

2. A Growing Threat to macOS

  • macOS has historically been seen as more secure than Windows.
  • The increased targeting of macOS users indicates a shift in attacker priorities.
  • Users relying on outdated security assumptions are at greater risk.

3. The Role of Malware-as-a-Service (MaaS)

  • The pay-per-install model allows multiple cybercriminals to leverage the same malware infrastructure.
  • This means ReaderUpdate could be used to deploy various types of malicious payloads, including ransomware or info-stealers.

4. Obfuscation and Evasion

– The

  • Future variants will likely adopt even more advanced obfuscation techniques to remain undetected.

5. Why Go is a Game Changer

  • While Rust and Nim are increasingly used for malware, the of Go-based variants suggests a new trend.
  • Go’s efficiency in cross-platform development may lead to multi-OS threats, where similar code runs on Windows, macOS, and Linux.

What This Means for Security

The evolution of ReaderUpdate serves as a wake-up call for macOS security. The traditional belief that “Macs don’t get viruses” no longer holds. Attackers are actively developing cross-platform, persistent, and stealthy malware, making it critical for users and organizations to:

– Regularly update macOS security settings and software.

– Avoid downloading applications from untrusted sources.

  • Use endpoint detection and response (EDR) tools capable of identifying emerging threats.
  • Monitor system activity for unusual processes or unauthorized modifications.

As malware authors continue to refine their tactics, security researchers and organizations must stay ahead of the curve to prevent large-scale infections.

Fact Checker Results

  • Confirmed malware evolution: Multiple security reports validate that ReaderUpdate has expanded to five programming languages.
  • Verified stealth techniques: Obfuscation and persistence strategies used by the malware are consistent with recent threat intelligence findings.
  • Documented macOS targeting: Security firms, including SentinelOne, have observed a growing focus on macOS infections in underground markets.

References:

Reported By: https://securityaffairs.com/175891/malware/readerupdate-malware-variants-targets-macos.html
Extra Source Hub:
https://www.reddit.com/r/AskReddit
Wikipedia
Undercode AI

Image Source:

Pexels
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 TelegramFeatured Image