Hackers Target Apple’s Mac Users With New Malware Hidden in Popular Apps

5Mind. The Meme Platform

Cybercriminals embedded malicious code and remote-control tools in software used for server management and secure connections.

A new variant of macOS malware known as ZuRu is targeting Apple users by embedding malicious code and a hacking tool into popular utilities used for remote connections and server management, cybersecurity researchers have warned.

First discovered in 2021, ZuRu has evolved over time and can now infect more apps and in new ways, cybersecurity firm SentinelOne said in a July 10 alert. Notably, the latest strain only works on Macs running the Sonoma 14.1 operating system, which Apple launched in October 2023, or Sequoia, its latest operating system.

Earlier versions of ZuRu were found hidden inside both pirated and legitimate copies of popular tools used by developers and IT professionals such as SecureCRT, Navicat, and Microsoft Remote Desktop for Mac. Most recently, the malware was found in a trojanized version of Termius, an app used for managing remote servers and secure network connections.

“This recent sample uses a new method to trojanize legitimate applications,” wrote Phil Stokes and Dinesh Devadoss, cybersecurity researchers at SentinelOne. They noted that the Trojanized version of Termius has had malicious code added to it, along with a helper program called a command-and-control (C2) implant, which allows attackers to remotely control infected Macs.

This particular C2 implant is based on Khepri, an open-source hacking tool designed to let attackers run commands and gather information from a compromised system, the researchers said. Once installed, the implant gives hackers powerful capabilities, including transferring files to or from the victim’s computer, running or controlling programs on the infected Mac, and executing commands and capturing whatever results or data those commands produce.

“The latest variant of macOS.ZuRu continues the threat actor’s pattern of trojanizing legitimate macOS applications used by developers and IT professionals,” the researchers noted. They added that attackers appear to have shifted from earlier, simpler methods to embedding malware in helper applications, likely in an effort to bypass modern security detection measures.

By Tom Ozimek

Read Full Article on TheEpochTimes.com

Contact Your Elected Officials
The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

Little Trump Cartoons Go VIRAL!

A YouTube channel launched December 20 of 2025 called “Little Trump: Donald Trump’s Cartoon Verse” is going viral for being hysterical as well as informational!

Anne Heche’s Posthumous Pedophile Revelations

There is unrest in Tinsel Town, as Hollywood used...

Real Protests Vs. Fake Protests

U.S. protesters seek to overturn the will of the people after a lawful election, while Iranians protest to end tyranny and establish it—a stark difference.

EU Commissar: Free Speech Is a Virus, Censorship the Vaccine

Ursula von der Leyen likened “malign information” to a virus, arguing society must be inoculated through “prebunking,” widely seen as censorship.

The family fault line

The future of humanity rests not upon government, but with the family. A principle that is as bold as it is true and profound.

DOJ Inquiry Into Fed Chair: What to Know

Powell said the DOJ threatened a criminal indictment against the central bank over over-budget renovations of headquarters and his congressional testimony.

Minnesota, Illinois Sue Trump Admin Over ICE Deployments

Minnesota sued the federal government over its recent surge of ICE agents to the Twin Cities, arguing that the surge is “unconstitutional and unlawful.”

Dan Bongino to Return as Radio Talk Show Host Next Month

Dan Bongino will be returning to hosting a radio and podcast show after he departed the FBI, where he had been serving as the bureau’s deputy director.

Protesters Clash with Federal Agents, Conservative Influencers Outside ICE Facility in Minnesota

Conflict between protesters and ICE officers continued on Jan. 11 outside a federal building that the agency is using as a detention facility.

Trump Says Countries Doing Business With Iran Will Pay 25 Percent Tariff

President Donald Trump announced on Jan. 12 that countries trading with Iran will face a 25 percent tariff.

Trump Provides Update on When $2,000 Tariff Payments Could Come

President Trump believes the administration does not need congressional approval to send out tariff-derived payments to Americans.

Trump to Meet Venezuelan Opposition Leader Machado as US Oversees Transition

President Trump will meet Venezuelan opposition leader María Corina Machado in Washington, as questions mount over Venezuela’s political future.

Trump Order Taking US Out of UN Climate Orgs Caps Flood of Corporate Exits

Trump put another dent in the ESG movement, withdrawing the U.S. from UNFCCC and 65 international organizations dedicated to climate and social justice.
spot_img

Related Articles