Trojan.MacOS.Jahlav.I is the detection for the Jahlav trojan for MacOS systems. There is nothing special about Jahlav. It is a Mac trojan that is distributed in fake crack or keygen programs on free download websites. In addition to being illegal, pirating hides other risks like getting infected with the Jahlav trojan.
Once Jahlav infects a Mac, it creates a malicious shell script file AdobeFlash in ~/Library/Internet Plug-Ins. Jahlav also schedules the script to run periodically. Within the first script there is another obfuscated script that in turn contains a Perl script with the true payload. The perl script uses HTTP to communicate with a C2. Jahlav can download code as instructed by the malware operator. This functionality means that the cybercriminals have a plethora of options to further compromise the infected system.