Hackers Target Apple’s Mac Users With New Malware Hidden in Popular Apps

5Mind. The Meme Platform

Cybercriminals embedded malicious code and remote-control tools in software used for server management and secure connections.

A new variant of macOS malware known as ZuRu is targeting Apple users by embedding malicious code and a hacking tool into popular utilities used for remote connections and server management, cybersecurity researchers have warned.

First discovered in 2021, ZuRu has evolved over time and can now infect more apps and in new ways, cybersecurity firm SentinelOne said in a July 10 alert. Notably, the latest strain only works on Macs running the Sonoma 14.1 operating system, which Apple launched in October 2023, or Sequoia, its latest operating system.

Earlier versions of ZuRu were found hidden inside both pirated and legitimate copies of popular tools used by developers and IT professionals such as SecureCRT, Navicat, and Microsoft Remote Desktop for Mac. Most recently, the malware was found in a trojanized version of Termius, an app used for managing remote servers and secure network connections.

“This recent sample uses a new method to trojanize legitimate applications,” wrote Phil Stokes and Dinesh Devadoss, cybersecurity researchers at SentinelOne. They noted that the Trojanized version of Termius has had malicious code added to it, along with a helper program called a command-and-control (C2) implant, which allows attackers to remotely control infected Macs.

This particular C2 implant is based on Khepri, an open-source hacking tool designed to let attackers run commands and gather information from a compromised system, the researchers said. Once installed, the implant gives hackers powerful capabilities, including transferring files to or from the victim’s computer, running or controlling programs on the infected Mac, and executing commands and capturing whatever results or data those commands produce.

“The latest variant of macOS.ZuRu continues the threat actor’s pattern of trojanizing legitimate macOS applications used by developers and IT professionals,” the researchers noted. They added that attackers appear to have shifted from earlier, simpler methods to embedding malware in helper applications, likely in an effort to bypass modern security detection measures.

By Tom Ozimek

Read Full Article on TheEpochTimes.com

Contact Your Elected Officials
The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

Viral Video Implicates Somalia Rep. Ilhan Omar

"Oh, what a tangled web we weave when first...

Homelessness, Inc.: When Misery Becomes an Industry

The honest term for a person living on the street, in a tent, under an overpass, or in their car is homeless. And honesty is what we need on this topic.

The World is Moving from Left to Right

Mainstream media claim Trump and the MAGA base are at record lows in popularity, but European election results and polls suggest a different reality.

Conservatives Against Trump Are Dead to Me!

Youth today use the expression “sus” when something is suspicious and many traditionally pro-Trump conservative podcasters have become extremely sus.

Fat Propaganda Roundup: ‘Housing Inequity’

Rampant obesity doesn’t afflict parts of the world that don’t have drive-thrus, don’t spray toxics on cash crops and refuse to walk anywhere for any reason.

Judge Tosses Charges Against Former Louisville Officers in Breonna Taylor Case

A federal judge threw out charges against two former Louisville police officers connected to ncident in which Breonna Taylor was shot and killed.

CDC Jeopardized Health of ‘Millions of Americans’ by Failing to Warn of Stroke Risk After Pfizer Vaccine

Sen. Ron Johnson obtained documents suggesting Biden officials downplayed COVID-19 vaccine risks and delayed warning the public.

Trump to Sign Order to Pay TSA Agents

President Trump plans to sign an order that will pay TSA agents who have not received a check since the DHS entered a partial shutdown in mid-February.

Trump–Kennedy Center Confirms Bill Maher Will Receive 27th Mark Twain Prize for American Humor

Comedian and TV host Bill Maher has been named as the 27th recipient for the prestigious Mark Twain Prize for American Humor.

Markwayne Mullin Sworn In as DHS Secretary

Former Oklahoma Senator Markwayne Mullin was sworn in at the White House as the new Secretary of the Department of Homeland Security (DHS).
00:27:39

US Looking to Seize Iranian Defectors’ Money: Bessent

Treasury Sec. Scott Bessent said that the US is moving to seize funds transferred abroad by Iranian defectors, so it can be to returned to the Iranian people.

Trump Says He’s ‘Not Putting Troops Anywhere’ Amid Iran War

President Donald Trump met with Japanese Prime Minister Sanae Takaichi to discuss the Iran war, saying he is not inclined to send U.S. ground troops.

US Agencies Terminated or Reduced 95 Wasteful Contracts Worth $2 Billion: DOGE

Federal agencies canceled or scaled back 95 wasteful contracts worth up to $2B in the last four weeks, saving taxpayers $757M.
spot_img

Related Articles

Popular Categories

MAGA Business Central