BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

New ZuRu macOS Malware Spreads via Trojanized Business Apps

  • Researchers identified new activity from the ZuRu macOS Malware in late May 2025.
  • ZuRu disguises itself as legitimate software, including the Termius SSH client, to infect Mac computers.
  • The malware uses a modified open-source toolkit called Khepri for remote access and control.
  • Attackers distribute ZuRu primarily through trojanized apps found via sponsored web searches.
  • Recent changes show the malware now uses new methods to bypass security on macOS systems.

Cybersecurity experts have detected fresh signs of ZuRu, a malware affecting Apple’s macOS, in May 2025. The malware spreads by imitating popular business and IT management applications, targeting users through altered installation files. ZuRu’s latest appearance involves mimicking the SSH client and server-management tool Termius.

- Advertisement -

According to a report from SentinelOne, researchers observed ZuRu using a fake version of Termius. Attackers delivered the malware via a .dmg disk image, which included a tampered application bundle signed with the threat actor’s own code signature. This particular method allows ZuRu to bypass macOS code signing restrictions.

The report notes that ZuRu employs a modified version of Khepri, an open-source toolkit that lets attackers remotely control infected systems. The malware installs extra executables, including a loader designed to fetch commands from an external server. “ZuRu malware continues to prey on macOS users seeking legitimate business tools, adapting its loader and C2 techniques to backdoor its targets,” researchers Phil Stokes and Dinesh Devadoss stated.

First documented in September 2021, ZuRu was known to hijack searches related to popular Mac tools like iTerm2. It directed users to fake websites, leading them to download malware-infected files. In January 2024, Jamf Threat Labs connected ZuRu to pirated apps, including Microsoft’s Remote Desktop for Mac, SecureCRT, and Navicat, all distributed with hidden malware.

The recent variant changes how it hides within apps. Instead of modifying the main executable with a malicious add-on, attackers now embed the threat inside a helper application. This adjustment appears aimed at dodging traditional malware detection. The loader checks for the presence of existing malware, verifies its integrity, and downloads updates if a mismatch is found.

- Advertisement -

The Khepri tool’s features include file transfers, system monitoring, running programs, and capturing output, all controlled via a remote server. Researchers note that the attackers focus on trojanizing tools commonly used by developers and IT professionals. They also rely on techniques such as persistence modules and beaconing methods to maintain their hold on compromised systems. More information can be found in SentinelOne’s detailed analysis.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Goldman Sachs buys NEOS for $2.25B, adds Bitcoin/Ether ETFs

Goldman Sachs has agreed to acquire ETF manager NEOS Investments for up to $2.25...

SEC innovation exemption allows 24/7 tokenized stock trading

The SEC is preparing an “innovation exemption” to enable 24/7 blockchain trading of tokenized...

Coldcard Hack Drives $15B Bitcoin Exodus to Safer Wallets

A firmware exploit targeting Coldcard hardware wallets drained approximately 2,100 BTC, with losses estimated...

Crypto OG Tone Vays admits ‘idiot’ move giving hackers PC access

Self-proclaimed crypto educator Tone Vays admitted he gave Hackers remote access to his PC...

Bitcoin dips below $63.5K despite US CPI matching expectations

Bitcoin dipped below $63,500 on Wednesday after US inflation data matched expectations, frustrating bulls...

Must Read

Forex Trading Vs Crypto Trading: Which One Should You Choose?

So you're trying to decide between two types of trading: Forex and cryptocurrency.Forex trading is the big player in the trading world, with lots...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading