macOS.ZuRu is a macOS malware operation associated with trojanized software distribution and targeting of Web3 and cryptocurrency-related users and platforms. It has been observed re-emerging with a modified Khepri command-and-control framework embedded in a trojanized version of the legitimate Termius SSH client. The activity is attributed to China. The operation is notable for abusing legitimate software as an initial-access vector and for focusing on victims in the cryptocurrency ecosystem, consistent with financially motivated malware campaigns aimed at theft of digital assets or related credentials. Known naming for this activity includes macOS.ZuRu.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.