Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The password gets written to ~/.config/zoom/data.json... hidden in a “cache” value in a base64-encoded format with randomly generated filler characters... [with] invisible zero-width Unicode characters... hidden within the file’s “version” field.
The Mach-O payload executable gets embedded within the dropper and extracted at runtime.
[The malware] first attempt[s] to execute [the embedded Mach-O payload] via /dev/fd without writing it to the disk.
The password gets written to a file... in a base64-encoded format with randomly generated filler characters placed before and after it.
“The malware arrives as a disk image designed to resemble a legitimate Zoom installer.”
It also accepts gzipped tar archives, which it unpacks with /usr/bin/tar.
The final payload... retrieves its command-and-control (C2) address from an encrypted configuration file and beacons every 8 to 16 seconds. The backdoor receives tasks from the C2 server as JSON objects.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A two-stage macOS backdoor delivered through a counterfeit Zoom disk-image installer. It socially engineers users to bypass Gatekeeper and enter their login password, uses that password locally to execute an embedded universal Mach-O second stage via sudo, creates a hidden working directory, surveys the host, and supports remote task execution including delivery and execution of binaries or archives. The analyzed samples did not exhibit persistence or built-in browser, Keychain, or cryptocurrency-wallet theft.
macOS backdoor distributed through a fake Zoom disk-image installer. The installer socially engineers users into bypassing Gatekeeper and captures their password, then extracts and executes a universal Mach-O payload. The implant beacons to C2, surveys the host, receives JSON tasking, and executes supplied raw Mach-O payloads or gzipped tar archives. It lacks observed browser/keychain/cryptocurrency-wallet theft and persistence mechanisms; the captured password is used to advance the attack chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.