Hackers Target Apple’s Mac Users With New Malware Hidden in Popular Apps

Contact Your Elected Officials

Cybercriminals embedded malicious code and remote-control tools in software used for server management and secure connections.

A new variant of macOS malware known as ZuRu is targeting Apple users by embedding malicious code and a hacking tool into popular utilities used for remote connections and server management, cybersecurity researchers have warned.

First discovered in 2021, ZuRu has evolved over time and can now infect more apps and in new ways, cybersecurity firm SentinelOne said in a July 10 alert. Notably, the latest strain only works on Macs running the Sonoma 14.1 operating system, which Apple launched in October 2023, or Sequoia, its latest operating system.

Earlier versions of ZuRu were found hidden inside both pirated and legitimate copies of popular tools used by developers and IT professionals such as SecureCRT, Navicat, and Microsoft Remote Desktop for Mac. Most recently, the malware was found in a trojanized version of Termius, an app used for managing remote servers and secure network connections.

“This recent sample uses a new method to trojanize legitimate applications,” wrote Phil Stokes and Dinesh Devadoss, cybersecurity researchers at SentinelOne. They noted that the Trojanized version of Termius has had malicious code added to it, along with a helper program called a command-and-control (C2) implant, which allows attackers to remotely control infected Macs.

This particular C2 implant is based on Khepri, an open-source hacking tool designed to let attackers run commands and gather information from a compromised system, the researchers said. Once installed, the implant gives hackers powerful capabilities, including transferring files to or from the victim’s computer, running or controlling programs on the infected Mac, and executing commands and capturing whatever results or data those commands produce.

“The latest variant of macOS.ZuRu continues the threat actor’s pattern of trojanizing legitimate macOS applications used by developers and IT professionals,” the researchers noted. They added that attackers appear to have shifted from earlier, simpler methods to embedding malware in helper applications, likely in an effort to bypass modern security detection measures.

By Tom Ozimek

Read Full Article on TheEpochTimes.com

The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

Doxed Democrats Are Getting Fired Left and Left

Not a misprint because a title of “left and...

Hold Up, Feds, Without Federalism, There Is No USA

Federalism is essential to governing the U.S., yet the federal government is undermining it by bribing states to implement unnecessary federal programs.

A Widow Inspires The World

Erika Kirk moved the nation with her speech two days after her husband’s assassination, vowing to continue his mission and grow Turning Point USA.

Both Left and Right Are Making Lists

The right admired Charlie Kirk for his faith and patriotism, while the left opposed him for dismantling their positions and narratives with ease.

Redemption’s playbook: The Senior

The Senior isn’t your usual underdog tale, it’s real, it’s raw, and it flips every cliché on its head with a playbook full of grit and plenty of aftermaths.

Trump Cannot Remove Fed Governor Lisa Cook for Now, Appeals Court Rules

A panel of federal judges on Monday held that President Donald Trump cannot fire Federal Reserve Governor Lisa Cook as of now.

FBI Looking Into Other Possible Charlie Kirk Assassination Accomplices: Deputy Director Bongino

FBI Deputy Dir. Dan Bongino said that the FBI is “looking into” other possible accomplices in the assassination of conservative influencer Charlie Kirk.

Actor Sean Astin, Known for ‘Rudy,’ ‘Lord of the Rings,’ Elected SAG-AFTRA President

Oscar-nominated actor Sean Astin, famed for Samwise in “Lord of the Rings,” has been elected as the new president of SAG-AFTRA.

RFK Jr. Names New Members to CDC Vaccine Advisory Panel

Health Secretary Robert F. Kennedy Jr. named 5 new members to the Advisory Committee on Immunization Practices, which advises the CDC on vaccines.

Trump Signs Memo Targeting Direct-to-Consumer Pharmaceutical Advertising

President Trump signed a memo to ensure drug ads give fair, balanced, and complete information to protect and inform American consumers.

Trump Runs out of Patience With China, Sharpens His Words

President Donald Trump’s recent remarks targeting China and its allies mark a noticeable shift in tone.

Trump Signs Order Renaming Department of Defense as Department of War

President Donald Trump on Sept. 5 signed an executive order renaming the Department of Defense as the Department of War.

Trump Signs Executive Order Targeting Countries That Unlawfully Detain Americans

President Trump signed an EO on targeting the unlawful detention of American citizens around the world and to facilitate the release of hostages.
spot_img

Related Articles