MacOS devices are being targeted by pirated apps that want to hijack your machine


Cybersecurity researchers from Jamf Threat Labs have uncovered a new piece of malware targeting macOS users.
The malware, though unnamed, shares many similarities with another malicious piece of code discovered in 2021, called ZuRu.
In a detailed report, the researchers said the malware was found hiding in three separate, pirated software. The software, including Microsoft Remote Desktop, was found on a Chinese website that provides links to different pirated applications.
The ghost of ZuRu
If a user downloads and runs any of the compromised applications, the malware will download and execute multiple payloads in the background. These payloads are all tasked with different things, from serving as a dropper, to being a backdoor, to working as a persistent downloader to deliver additional malicious payloads.
The targets, obviously, seem to be Chinese macOS users, similar to what ZuRu did three years ago.
Back in 2021, cybersecurity researchers from Objective-See and Trend Micro observed ZuRu hiding in pirated versions of applications such as iTerm, SecureCRT, Navicat Premium, and Remote Desktop Client. The people that downloaded these apps found them working as intended, but were oblivious to the fact that a Python script was being executed in the background.
This script stole sensitive data from the victim endpoint and sent them to a command & control (C2) server used by the attackers.
“It’s possible that this malware is a successor to the ZuRu malware given its targeted applications, modified load commands and attacker infrastructure,” Jamf’s researchers said.
Pirated software is a great place to hide malware, the researchers also added, as users understand they’re engaged in illegal activity and expect their antivirus programs to raise a flag. “This leaves them willing to skip past any security warning prompts built into the operating system such as Gatekeeper, which informs the user that these applications are not safe to open,” they concluded.
Thus, the best way to protect against such threats is not to steal and download pirated software in the first place.
More from TechRadar Pro
Cybersecurity researchers from Jamf Threat Labs have uncovered a new piece of malware targeting macOS users. The malware, though unnamed, shares many similarities with another malicious piece of code discovered in 2021, called ZuRu. In a detailed report, the researchers said the malware was found hiding in three separate, pirated…
Recent Posts
- OpenSSH vulnerabilities could pose huge threat to businesses everywhere
- Magic: The Gathering’s Final Fantasy sets will tell the stories of the games
- All of Chipolo’s Bluetooth trackers are discounted in sitewide sale
- Fortnite: Lawless gets first trailer highlighting the new season’s battle pass roster and the chaos of Crime City
- Chase will start blocking Zelle payments over social media
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010