OSX.ZuRu is a macOS malware family distributed through trojanized versions of legitimate applications, notably terminal, remote access, and database client software. It was observed in campaigns that abused sponsored search results to lure users to counterfeit download sites serving altered application bundles. The malware modifies otherwise legitimate macOS apps to load a malicious dynamic library at startup, allowing code execution as soon as the trojanized application launches.
The implanted library acts as a first-stage loader and backdoor component. It gathers a host identifier, communicates with command-and-control infrastructure, and executes server-supplied shell commands to retrieve and run additional payloads. Reported second-stage components included a Python-based reconnaissance and theft module that surveyed the infected host and collected sensitive data such as SSH keys, keychain material, shell history, and other system information, as well as an additional payload associated with Cobalt Strike activity. This establishes OSX.ZuRu as both a delivery mechanism for follow-on tooling and a direct data-theft threat.
OSX.ZuRu has been linked to campaigns targeting macOS users in China, including Baidu users searching for popular software. Known lures included trojanized builds of iTerm2, SecureCRT, Microsoft Remote Desktop for Mac, and Navicat. Its observed behavior combines dylib-based execution hijacking, host reconnaissance, payload retrieval, command execution, and exfiltration of stolen data. The malware is notable for illustrating how macOS users can be compromised through poisoned software distribution channels rather than exploits alone.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
macOS malware distributed via trojanized admin/networking tools that drops a Python component to copy and exfiltrate SSH keys and other data from infected systems.
macOS malware delivered via trojanized applications distributed through sponsored search results. The trojanized app adds an LC_LOAD_DYLIB dependency to a malicious library (libcrypto.2.dylib) that executes automatically via an Objective-C +load method, fingerprints the host (serial number), contacts a remote URL, and runs shell commands to download and execute additional payloads (a Python survey/exfil script and a Mach-O binary).
OSX.ZuRu is a macOS malware distributed via trojanized applications and sponsored search results, using stealthy techniques and delivering additional payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.