{"id":85531,"date":"2019-01-29T20:24:23","date_gmt":"2019-01-30T04:24:23","guid":{"rendered":"https:\/\/www.intego.com\/mac-security-blog\/?p=85531"},"modified":"2026-07-02T01:32:21","modified_gmt":"2026-07-02T08:32:21","slug":"verymal-mac-attack-hides-data-within-a-picture","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/verymal-mac-attack-hides-data-within-a-picture\/","title":{"rendered":"VeryMal Mac attack hides data within a picture"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-52468\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/04\/fake-flash-600x300.jpeg\" alt=\"\" width=\"600\" height=\"300\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/04\/fake-flash-600x300.jpeg 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/04\/fake-flash-600x300-150x75.jpeg 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/04\/fake-flash-600x300-300x150.jpeg 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/>A recent malware distribution campaign dubbed &#8220;VeryMal&#8221; leverages an ancient technique called steganography\u2014the hiding of secret information in plain sight\u2014to distribute Mac malware.<\/p>\n<p>The VeryMal campaign was caught distributing <a href=\"https:\/\/www.intego.com\/mac-security-blog\/topic\/osxshlayer\/\" target=\"_blank\" rel=\"noopener\">OSX\/Shlayer<\/a>, which was originally discovered by Intego researchers one year ago.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-75805\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/02\/Shlayer_A_download_step_2_Chrome-1024x572.jpg\" alt=\"\" width=\"1024\" height=\"572\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/02\/Shlayer_A_download_step_2_Chrome-1024x572.jpg 1024w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/02\/Shlayer_A_download_step_2_Chrome-150x84.jpg 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/02\/Shlayer_A_download_step_2_Chrome-300x168.jpg 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/02\/Shlayer_A_download_step_2_Chrome-768x429.jpg 768w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/02\/Shlayer_A_download_step_2_Chrome-657x367.jpg 657w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/02\/Shlayer_A_download_step_2_Chrome.jpg 1392w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p style=\"text-align: center;\">OSX\/Shlayer malware still masquerades as a fake Flash Player.<\/p>\n<h3>What makes this malware campaign unique?<\/h3>\n<p>Although the concept of <a href=\"https:\/\/en.wikipedia.org\/wiki\/Steganography\" target=\"_blank\" rel=\"noopener\">steganography<\/a> has been around for hundreds of years, it is not something we see in a lot of Mac malware campaigns.<\/p>\n<p>The VeryMal campaign used some cleverly crafted JavaScript code to look for secret information stored within a seemingly innocuous JPEG image file. The hidden data tells the site where to go to find the malware.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-85534\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2019\/01\/sscc_jpg-steganographic-image-screenshot-via-blog_confiant_com-cropped.png\" alt=\"\" width=\"528\" height=\"195\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2019\/01\/sscc_jpg-steganographic-image-screenshot-via-blog_confiant_com-cropped.png 528w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2019\/01\/sscc_jpg-steganographic-image-screenshot-via-blog_confiant_com-cropped-150x55.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2019\/01\/sscc_jpg-steganographic-image-screenshot-via-blog_confiant_com-cropped-300x111.png 300w\" sizes=\"auto, (max-width: 528px) 100vw, 528px\" \/><\/p>\n<p style=\"text-align: center;\">To the naked eye, the image looks like a plain, white rectangle. Credit: <a href=\"https:\/\/blog.confiant.com\/confiant-malwarebytes-uncover-steganography-based-ad-payload-that-drops-shlayer-trojan-on-mac-cd31e885c202\" target=\"_blank\" rel=\"noopener\">Stein<\/a><\/p>\n<p>Why go to all this trouble? In theory, using steganography or other <a href=\"https:\/\/en.wikipedia.org\/wiki\/Obfuscation_(software)\" target=\"_blank\" rel=\"noopener\">obfuscation<\/a> techniques makes it more difficult for endpoint protection and network monitoring software to determine that something suspicious might be happening.<\/p>\n<p>In practice, however, this tricky tactic does not prevent well-designed antivirus software like VirusBarrier X9 from keeping users safe.<\/p>\n<h3>Is my Mac infected?<\/h3>\n<p>Users of Intego VirusBarrier X9 (part of Intego&#8217;s\u00a0<a href=\"https:\/\/www.intego.com\/mac-protection-bundle\" target=\"_blank\" rel=\"noopener\">Mac Premium Bundle X9<\/a>\u00a0suite) or\u00a0<a href=\"https:\/\/www.intego.com\/products\/intego-one-mac\" target=\"_blank\" rel=\"noopener\">Flextivity<\/a>\u00a0<strong>were already protected<\/strong> from this threat before the discovery of the VeryMal campaign.<\/p>\n<p><strong>If you aren&#8217;t a VirusBarrier X9 user<\/strong> and you think you might have downloaded a fake Flash Player, you can scan your Mac with <a href=\"https:\/\/www.intego.com\/virusbarrier-scanner\" target=\"_blank\" rel=\"noopener\">VirusBarrier Scanner<\/a> (available for <a href=\"https:\/\/itunes.apple.com\/us\/app\/virusbarrier-scanner\/id1200445649\" target=\"_blank\" rel=\"noopener\">free<\/a> on the Mac App Store) to check for any infections. After you scan your Mac, your best bet to <strong>prevent future infections<\/strong> is to <a href=\"https:\/\/www.intego.com\/buynow\" target=\"_blank\" rel=\"noopener\">get VirusBarrier X9<\/a>, which includes <a href=\"https:\/\/www.intego.com\/mac-security-blog\/why-your-antivirus-needs-real-time-scanning\/\" target=\"_blank\" rel=\"noopener\">real-time scanning<\/a> functionality\u2014a critical feature to block malware before it can harm your Mac.<\/p>\n<h3>How sysadmins can find potentially infected Macs<\/h3>\n<p>If you&#8217;re a systems administrator and want to check for potentially infected Macs on your network, you can check whether any Macs phoned home to one of the following sites (remove the space before each .com):<\/p>\n<pre>veryield-malyst .com\r\ns.ad-pixel .com\/sscc.jpg<\/pre>\n<p>Any Mac that made contact with those sites around mid-January 2019 may be infected with Shlayer malware.<\/p>\n<h3>How can I learn more?<\/h3>\n<p>For more technical details about the malware, you can read Eliya Stein&#8217;s <a href=\"https:\/\/blog.confiant.com\/confiant-malwarebytes-uncover-steganography-based-ad-payload-that-drops-shlayer-trojan-on-mac-cd31e885c202\" target=\"_blank\" rel=\"noopener\">write-up<\/a>.<\/p>\n<p><a href=\"https:\/\/itunes.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-thumbnail wp-image-71818\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-150x150.png\" alt=\"\" width=\"50\" height=\"50\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-150x150.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-32x32.png 32w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-50x50.png 50w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-64x64.png 64w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-96x96.png 96w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-128x128.png 128w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile.png 300w\" sizes=\"auto, (max-width: 50px) 100vw, 50px\" \/><\/a>Each week, we talk about the latest Apple security news on the <strong>Intego Mac Podcast<\/strong>, so be sure to <a href=\"https:\/\/itunes.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" target=\"_blank\" rel=\"noopener\">subscribe<\/a> to make sure you don&#8217;t miss any episodes. You&#8217;ll also want to subscribe to our <strong>e-mail newsletter<\/strong> and keep an eye here on <strong>The Mac Security Blog<\/strong> for updates.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A recent malware distribution campaign dubbed &#8220;VeryMal&#8221; leverages an ancient technique called steganography\u2014the hiding of secret information in plain sight\u2014to distribute Mac malware. The VeryMal campaign was caught distributing OSX\/Shlayer, which was originally discovered by Intego researchers one year ago. OSX\/Shlayer malware still masquerades as a fake Flash Player. What makes this malware campaign unique? [&hellip;]<\/p>\n","protected":false},"author":14,"featured_media":52474,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[190],"tags":[3928],"class_list":["post-85531","post","type-post","status-publish","format-standard","has-post-thumbnail","category-malware","tag-osxshlayer"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"A recent malware distribution campaign dubbed &quot;VeryMal&quot; leverages an ancient technique called steganography\u2014the hiding of secret information in plain sight\u2014to distribute Mac malware. The VeryMal campaign was caught distributing OSX\/Shlayer, which was originally discovered by Intego researchers one year ago. OSX\/Shlayer malware still masquerades as a fake Flash Player. What makes this malware campaign unique?\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Joshua Long\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/verymal-mac-attack-hides-data-within-a-picture\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"The Mac Security Blog - Keep Macs safe from the dangers of the Internet\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"VeryMal Mac attack hides data within a picture\" \/>\n\t\t<meta property=\"og:description\" content=\"A recent malware distribution campaign dubbed &quot;VeryMal&quot; leverages an ancient technique called steganography\u2014the hiding of secret information in plain sight\u2014to distribute Mac malware. The VeryMal campaign was caught distributing OSX\/Shlayer, which was originally discovered by Intego researchers one year ago. OSX\/Shlayer malware still masquerades as a fake Flash Player. What makes this malware campaign unique?\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/verymal-mac-attack-hides-data-within-a-picture\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-01-30T04:24:23+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-07-02T08:32:21+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/integogroup\/\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@IntegoSecurity\" \/>\n\t\t<meta name=\"twitter:title\" content=\"VeryMal Mac attack hides data within a picture\" \/>\n\t\t<meta name=\"twitter:description\" content=\"A recent malware distribution campaign dubbed &quot;VeryMal&quot; leverages an ancient technique called steganography\u2014the hiding of secret information in plain sight\u2014to distribute Mac malware. The VeryMal campaign was caught distributing OSX\/Shlayer, which was originally discovered by Intego researchers one year ago. OSX\/Shlayer malware still masquerades as a fake Flash Player. What makes this malware campaign unique?\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@IntegoSecurity\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/verymal-mac-attack-hides-data-within-a-picture\\\/#blogposting\",\"name\":\"VeryMal Mac attack hides data within a picture\",\"headline\":\"VeryMal Mac attack hides data within a picture\",\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/joshlong\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2016\\\/04\\\/fake-flash-400x260.jpeg\",\"width\":400,\"height\":260,\"caption\":\"Fake Flash Player installers continue to be used by OSX\\\/Adload and OSX\\\/Bundlore malware\"},\"datePublished\":\"2019-01-29T20:24:23-08:00\",\"dateModified\":\"2026-07-02T01:32:21-07:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/verymal-mac-attack-hides-data-within-a-picture\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/verymal-mac-attack-hides-data-within-a-picture\\\/#webpage\"},\"articleSection\":\"Malware, OSX\\\/Shlayer, joshlong\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/verymal-mac-attack-hides-data-within-a-picture\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/malware\\\/#listItem\",\"name\":\"Malware\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/malware\\\/#listItem\",\"position\":2,\"name\":\"Malware\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/malware\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/verymal-mac-attack-hides-data-within-a-picture\\\/#listItem\",\"name\":\"VeryMal Mac attack hides data within a picture\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/verymal-mac-attack-hides-data-within-a-picture\\\/#listItem\",\"position\":3,\"name\":\"VeryMal Mac attack hides data within a picture\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/malware\\\/#listItem\",\"name\":\"Malware\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/logo2.png\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/verymal-mac-attack-hides-data-within-a-picture\\\/#organizationLogo\",\"width\":122,\"height\":46},\"image\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/verymal-mac-attack-hides-data-within-a-picture\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/integogroup\\\/\",\"https:\\\/\\\/x.com\\\/IntegoSecurity\",\"https:\\\/\\\/www.instagram.com\\\/intego_security\\\/\",\"https:\\\/\\\/www.youtube.com\\\/user\\\/IntegoVideo\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/intego\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/joshlong\\\/#author\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/joshlong\\\/\",\"name\":\"Joshua Long\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/verymal-mac-attack-hides-data-within-a-picture\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ed8c9b8cc8610160efb5aa95bc28a7a0d5a23ce9b8959054305b11094bf0485a?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Joshua Long\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/verymal-mac-attack-hides-data-within-a-picture\\\/#webpage\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/verymal-mac-attack-hides-data-within-a-picture\\\/\",\"name\":\"VeryMal Mac attack hides data within a picture\",\"description\":\"A recent malware distribution campaign dubbed \\\"VeryMal\\\" leverages an ancient technique called steganography\\u2014the hiding of secret information in plain sight\\u2014to distribute Mac malware. The VeryMal campaign was caught distributing OSX\\\/Shlayer, which was originally discovered by Intego researchers one year ago. OSX\\\/Shlayer malware still masquerades as a fake Flash Player. What makes this malware campaign unique?\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/verymal-mac-attack-hides-data-within-a-picture\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/joshlong\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/joshlong\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2016\\\/04\\\/fake-flash-400x260.jpeg\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/verymal-mac-attack-hides-data-within-a-picture\\\/#mainImage\",\"width\":400,\"height\":260,\"caption\":\"Fake Flash Player installers continue to be used by OSX\\\/Adload and OSX\\\/Bundlore malware\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/verymal-mac-attack-hides-data-within-a-picture\\\/#mainImage\"},\"datePublished\":\"2019-01-29T20:24:23-08:00\",\"dateModified\":\"2026-07-02T01:32:21-07:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>VeryMal Mac attack hides data within a picture<\/title>\n\n","aioseo_head_json":{"title":"VeryMal Mac attack hides data within a picture","description":"A recent malware distribution campaign dubbed \"VeryMal\" leverages an ancient technique called steganography\u2014the hiding of secret information in plain sight\u2014to distribute Mac malware. The VeryMal campaign was caught distributing OSX\/Shlayer, which was originally discovered by Intego researchers one year ago. OSX\/Shlayer malware still masquerades as a fake Flash Player. What makes this malware campaign unique?","canonical_url":"https:\/\/www.intego.com\/mac-security-blog\/verymal-mac-attack-hides-data-within-a-picture\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/www.intego.com\/mac-security-blog\/verymal-mac-attack-hides-data-within-a-picture\/#blogposting","name":"VeryMal Mac attack hides data within a picture","headline":"VeryMal Mac attack hides data within a picture","author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/#author"},"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/04\/fake-flash-400x260.jpeg","width":400,"height":260,"caption":"Fake Flash Player installers continue to be used by OSX\/Adload and OSX\/Bundlore malware"},"datePublished":"2019-01-29T20:24:23-08:00","dateModified":"2026-07-02T01:32:21-07:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/verymal-mac-attack-hides-data-within-a-picture\/#webpage"},"isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/verymal-mac-attack-hides-data-within-a-picture\/#webpage"},"articleSection":"Malware, OSX\/Shlayer, joshlong"},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/verymal-mac-attack-hides-data-within-a-picture\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/#listItem","name":"Malware"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/#listItem","position":2,"name":"Malware","item":"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/verymal-mac-attack-hides-data-within-a-picture\/#listItem","name":"VeryMal Mac attack hides data within a picture"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/verymal-mac-attack-hides-data-within-a-picture\/#listItem","position":3,"name":"VeryMal Mac attack hides data within a picture","previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/#listItem","name":"Malware"}}]},{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","url":"https:\/\/www.intego.com\/mac-security-blog\/","logo":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2026\/08\/logo2.png","@id":"https:\/\/www.intego.com\/mac-security-blog\/verymal-mac-attack-hides-data-within-a-picture\/#organizationLogo","width":122,"height":46},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/verymal-mac-attack-hides-data-within-a-picture\/#organizationLogo"},"sameAs":["https:\/\/www.facebook.com\/integogroup\/","https:\/\/x.com\/IntegoSecurity","https:\/\/www.instagram.com\/intego_security\/","https:\/\/www.youtube.com\/user\/IntegoVideo","https:\/\/www.linkedin.com\/company\/intego"]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/#author","url":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/","name":"Joshua Long","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/verymal-mac-attack-hides-data-within-a-picture\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/ed8c9b8cc8610160efb5aa95bc28a7a0d5a23ce9b8959054305b11094bf0485a?s=96&d=mm&r=g","width":96,"height":96,"caption":"Joshua Long"}},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/verymal-mac-attack-hides-data-within-a-picture\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/verymal-mac-attack-hides-data-within-a-picture\/","name":"VeryMal Mac attack hides data within a picture","description":"A recent malware distribution campaign dubbed \"VeryMal\" leverages an ancient technique called steganography\u2014the hiding of secret information in plain sight\u2014to distribute Mac malware. The VeryMal campaign was caught distributing OSX\/Shlayer, which was originally discovered by Intego researchers one year ago. OSX\/Shlayer malware still masquerades as a fake Flash Player. What makes this malware campaign unique?","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/verymal-mac-attack-hides-data-within-a-picture\/#breadcrumblist"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/#author"},"creator":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/04\/fake-flash-400x260.jpeg","@id":"https:\/\/www.intego.com\/mac-security-blog\/verymal-mac-attack-hides-data-within-a-picture\/#mainImage","width":400,"height":260,"caption":"Fake Flash Player installers continue to be used by OSX\/Adload and OSX\/Bundlore malware"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/verymal-mac-attack-hides-data-within-a-picture\/#mainImage"},"datePublished":"2019-01-29T20:24:23-08:00","dateModified":"2026-07-02T01:32:21-07:00"},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"The Mac Security Blog - Keep Macs safe from the dangers of the Internet","og:type":"article","og:title":"VeryMal Mac attack hides data within a picture","og:description":"A recent malware distribution campaign dubbed &quot;VeryMal&quot; leverages an ancient technique called steganography\u2014the hiding of secret information in plain sight\u2014to distribute Mac malware. The VeryMal campaign was caught distributing OSX\/Shlayer, which was originally discovered by Intego researchers one year ago. OSX\/Shlayer malware still masquerades as a fake Flash Player. What makes this malware campaign unique?","og:url":"https:\/\/www.intego.com\/mac-security-blog\/verymal-mac-attack-hides-data-within-a-picture\/","article:published_time":"2019-01-30T04:24:23+00:00","article:modified_time":"2026-07-02T08:32:21+00:00","article:publisher":"https:\/\/www.facebook.com\/integogroup\/","twitter:card":"summary_large_image","twitter:site":"@IntegoSecurity","twitter:title":"VeryMal Mac attack hides data within a picture","twitter:description":"A recent malware distribution campaign dubbed &quot;VeryMal&quot; leverages an ancient technique called steganography\u2014the hiding of secret information in plain sight\u2014to distribute Mac malware. The VeryMal campaign was caught distributing OSX\/Shlayer, which was originally discovered by Intego researchers one year ago. OSX\/Shlayer malware still masquerades as a fake Flash Player. What makes this malware campaign unique?","twitter:creator":"@IntegoSecurity"},"aioseo_meta_data":{"post_id":"85531","title":null,"description":null,"keywords":null,"keyphrases":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_custom_url":null,"og_image_custom_fields":null,"og_image_url":null,"og_image_width":null,"og_image_height":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_image_url":null,"twitter_title":null,"twitter_description":null,"schema_type":"default","schema_type_options":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"limit_modified_date":false,"ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":"2026-09-03 13:58:59","created":"2026-09-03 13:58:59","updated":"2026-09-03 13:58:59","reviewed_by":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/\" title=\"Malware\">Malware<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tVeryMal Mac attack hides data within a picture\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.intego.com\/mac-security-blog"},{"label":"Malware","link":"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/"},{"label":"VeryMal Mac attack hides data within a picture","link":"https:\/\/www.intego.com\/mac-security-blog\/verymal-mac-attack-hides-data-within-a-picture\/"}],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/85531","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=85531"}],"version-history":[{"count":7,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/85531\/revisions"}],"predecessor-version":[{"id":105386,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/85531\/revisions\/105386"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/52474"}],"wp:attachment":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=85531"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=85531"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=85531"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}