Hackers Target Apple’s Mac Users With New Malware Hidden in Popular Apps

5Mind. The Meme Platform

Cybercriminals embedded malicious code and remote-control tools in software used for server management and secure connections.

A new variant of macOS malware known as ZuRu is targeting Apple users by embedding malicious code and a hacking tool into popular utilities used for remote connections and server management, cybersecurity researchers have warned.

First discovered in 2021, ZuRu has evolved over time and can now infect more apps and in new ways, cybersecurity firm SentinelOne said in a July 10 alert. Notably, the latest strain only works on Macs running the Sonoma 14.1 operating system, which Apple launched in October 2023, or Sequoia, its latest operating system.

Earlier versions of ZuRu were found hidden inside both pirated and legitimate copies of popular tools used by developers and IT professionals such as SecureCRT, Navicat, and Microsoft Remote Desktop for Mac. Most recently, the malware was found in a trojanized version of Termius, an app used for managing remote servers and secure network connections.

“This recent sample uses a new method to trojanize legitimate applications,” wrote Phil Stokes and Dinesh Devadoss, cybersecurity researchers at SentinelOne. They noted that the Trojanized version of Termius has had malicious code added to it, along with a helper program called a command-and-control (C2) implant, which allows attackers to remotely control infected Macs.

This particular C2 implant is based on Khepri, an open-source hacking tool designed to let attackers run commands and gather information from a compromised system, the researchers said. Once installed, the implant gives hackers powerful capabilities, including transferring files to or from the victim’s computer, running or controlling programs on the infected Mac, and executing commands and capturing whatever results or data those commands produce.

“The latest variant of macOS.ZuRu continues the threat actor’s pattern of trojanizing legitimate macOS applications used by developers and IT professionals,” the researchers noted. They added that attackers appear to have shifted from earlier, simpler methods to embedding malware in helper applications, likely in an effort to bypass modern security detection measures.

By Tom Ozimek

Read Full Article on TheEpochTimes.com

Contact Your Elected Officials
The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

The Iran War Allows Congress to Make Itself Relevant Again

Congress has made itself irrelevant by submitting to presidential power. The Iran War gives Congress the ability to refuse to spend on undeclared wars.

Albin Sadar Cartoons

Over the past twelve years, Albin Sadar has drawn cartoons for conservative websites like American Thinker, American Greatness, and now for The Thinking Conservative.

Hanoi Jane Typifies Hollywood Idiocy

After the United States and Israel launched military operations in Iran, wacky Jane Fonda decided to insert herself into the news again.

DHS Sec. Drops Jarring Intel on Intra-Agency Spies, U.S. Scientists Colluding With Wuhan Pre-COVID

As if she were discussing a picnic spread, DHS Secretary Krisi Noem nonchalantly spills the beans to Patrick Bet-David, February X, 2026:

The US Military Campaign Against Iran Is Part Of Trump’s Grand Strategy Against China

Trump claimed that the US’ military campaign against Iran is to “defend the American people”, but few observers realize that it’s actually all about China.

Father of Georgia High School Shooting Suspect Found Guilty of Murder Charges

A Georgia jury found a father guilty of murder for giving his son a rifle prosecutors say was used in a deadly 2024 school shooting, holding him responsible.

Texas Gov. Abbott Warns of Possible Iranian Terrorist ‘Sleeper Cells’ in His State

“We made clear to the public that the state of Texas is taking seriously the possibility of terrorist activity, lone wolf, lone wolf activity,” Abbott said.

Californians Expected to Decide on Voter ID in November

Californians are expected to be asked on the Nov. 3 ballot whether or not they want voter ID to be required in future elections.

Democrats Split on Trump’s Iran Strikes as War Powers Debate Looms

Congressional leaders of the Democratic Party have mostly been quick to decry President Donald Trump and Israel’s joint operation in Iran.

President Donald Trump Gives Update on Operation Epic Fury

Over the past 36 hours, the US and its partners have launched Operation Epic Fury, one of the largest, most complex, most overwhelming military offensives the world has ever seen.

Trump Announces US Military Sank 9 Iranian Navy Ships

President Trump said that the U.S. military has sunk nine Iranian naval ships and “largely destroyed” the regime’s naval headquarters.

Trump Agrees to Talk to New Iranian Leadership

President Donald Trump has agreed to open discussions with Iran’s newly established leadership following the death of Supreme Leader Ali Khamenei.

Trump’s Full Statement on Iran

President Trump announced that the United States had begun “major combat operations” in Iran with the goal of eliminating threats from the Iranian regime.
spot_img

Related Articles

Popular Categories

MAGA Business Central