ZuRu is a macOS malware family distributed through trojanized versions of legitimate applications hosted on fake or impersonating software sites, including campaigns promoted through malicious sponsored search results. Known lures have included repackaged remote access, terminal, and database tools such as iTerm2, Termius, SecureCRT, Microsoft Remote Desktop, and Navicat. The malware abuses user trust in expected software downloads and can require the victim to manually override macOS security prompts, enabling execution despite Gatekeeper protections.
ZuRu has been observed loading malicious components from within repackaged application bundles and then retrieving additional payloads from attacker-controlled infrastructure. Documented activity includes execution of a Python-based spyware component detected as TrojanSpy.Python.ZURU.A and installation of a Cobalt Strike agent for follow-on access. The spyware component performs broad host reconnaissance and data theft, collecting system and user information, installed application details, shell histories, SSH-related material, keychain data, application configuration data, and directory contents from common user locations before exfiltrating the results.
The malware is associated with multi-stage intrusion activity rather than simple commodity adware delivery. Its use of trojanized macOS software installers, staged payload retrieval, and post-compromise beacon deployment indicates an operator focused on establishing access and harvesting valuable local data from Mac users. Observed targeting is consistent with opportunistic compromise of individuals and organizations that rely on macOS productivity, administration, and remote access tools.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
macOS malware propagated via trojanized legitimate apps (e.g., Termius) targeting developers (per summary).
macOS trojan observed embedded in a trojanized Termius app; relies on user trust and manual Gatekeeper override to execute.
macOS trojan referenced as an example of malware delivered via a trojanized application DMG; in this article its DMG is used as a comparison against Shlayer-modified DMGs.
A first-stage downloader distributed via malicious ads, exfiltrates system survey data and installs a Cobalt Strike agent for further exploitation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.