Hackers Target Apple’s Mac Users With New Malware Hidden in Popular Apps

Contact Your Elected Officials

Cybercriminals embedded malicious code and remote-control tools in software used for server management and secure connections.

A new variant of macOS malware known as ZuRu is targeting Apple users by embedding malicious code and a hacking tool into popular utilities used for remote connections and server management, cybersecurity researchers have warned.

First discovered in 2021, ZuRu has evolved over time and can now infect more apps and in new ways, cybersecurity firm SentinelOne said in a July 10 alert. Notably, the latest strain only works on Macs running the Sonoma 14.1 operating system, which Apple launched in October 2023, or Sequoia, its latest operating system.

Earlier versions of ZuRu were found hidden inside both pirated and legitimate copies of popular tools used by developers and IT professionals such as SecureCRT, Navicat, and Microsoft Remote Desktop for Mac. Most recently, the malware was found in a trojanized version of Termius, an app used for managing remote servers and secure network connections.

“This recent sample uses a new method to trojanize legitimate applications,” wrote Phil Stokes and Dinesh Devadoss, cybersecurity researchers at SentinelOne. They noted that the Trojanized version of Termius has had malicious code added to it, along with a helper program called a command-and-control (C2) implant, which allows attackers to remotely control infected Macs.

This particular C2 implant is based on Khepri, an open-source hacking tool designed to let attackers run commands and gather information from a compromised system, the researchers said. Once installed, the implant gives hackers powerful capabilities, including transferring files to or from the victim’s computer, running or controlling programs on the infected Mac, and executing commands and capturing whatever results or data those commands produce.

“The latest variant of macOS.ZuRu continues the threat actor’s pattern of trojanizing legitimate macOS applications used by developers and IT professionals,” the researchers noted. They added that attackers appear to have shifted from earlier, simpler methods to embedding malware in helper applications, likely in an effort to bypass modern security detection measures.

By Tom Ozimek

Read Full Article on TheEpochTimes.com

The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

Five Reasons Why The Latest Czech Elections Were So Important

Populist-nationalist politician Andrej Babis is poised to return to the premiership after his party's victory. Here are 5 reasons why this is so important.

Bad Bunny is the NFL’s Latest Insult

After years of advocating social justice causes, the NFL chose left wing, gender fluid rapper Bad Bunny to headline the next Super Bowl. Does the NFL want conservatives fans?

Scheduling collides with legacy

The ACC’s footprint now sprawls from Boston and Miami to Salt Lake City and the San Francisco Bay, defying both geography and its own name.

The Paradoxical Patriot: The political odyssey of Frank S. Meyer

In his book, Daniel J. Flynn examines the ideological evolution of one of conservatism’s most paradoxical and overlooked architects, Frank S. Meyer. 

This Is America: Target™ Reparations

“This Is America” explores the cultural undercurrents pulling Western...

Judge Upholds Nassau County Ban on Transgender Athletes in Women’s Sports

A New York judge on Oct. 6 upheld a Long Island county law banning male athletes from participating in women’s sports at county-run facilities.

Takeaways From Pam Bondi’s Testimony Before Senate Panel

AG Pam Bondi testified before the Senate Judiciary Committee, defending some of the Justice Department’s moves while sparring with Democratic senators.

FBI Surveilled 8 GOP Members of Congress, Document Shows

The FBI surveilled Republican senators as part of its Arctic Frost investigation, a newly disclosed document shows.

Acting CDC Director Calls on Manufacturers to Break MMR Vaccine Into Separate Shots

A commonly used combination vaccine against measles should be replaced with separate shots, the acting director of the CDC said on Oct. 6.

Trump Says He May Invoke Insurrection Act in Portland If Necessary

President Donald Trump on Oct. 6 said he may consider invoking the Insurrection Act in Portland, Oregon, if necessary.

Trump: All Medium, Heavy Duty Trucks Entering US Will See 25 Percent Tariff on Nov. 1

President Trump announced on Monday that all medium and heavy-duty trucks entering the United States will see a 25 percent tariff starting on Nov. 1.

Treasury Names Social Security Commissioner as CEO of IRS

Treasury Sec. Scott Bessent announced that Frank Bisignano, the head of the Social Security Administration (SSA), will also serve as CEO of the IRS.

Agencies Terminated, Descoped 94 Wasteful Contracts With $8.5 Billion Ceiling Value, Says DOGE

Various federal government agencies have terminated and descoped 94 wasteful contracts over the past five days, DOGE said in an Oct. 4 post on X.
spot_img

Related Articles

Popular Categories

MAGA Business Central