A fake iTerm2 website, iterm2.net, impersonated the legitimate iterm2.com page and distributed a trojanized macOS installer through a malicious DMG hosted on related infrastructure. Researchers found the altered app was signed with an Apple Distribution certificate tied to “Jun Bi (AQPZ6F3ASY)” but was not notarized; Apple later revoked the certificate. The malware added a malicious dynamic library dependency, causing libcrypto.2.dylib to load automatically and contact attacker-controlled servers after execution.
The implanted library sent host identifiers including the Mac serial number to remote infrastructure, executed server-supplied shell commands, and fetched second-stage payloads including a Python script, g.py, and a Mach-O binary named GoogleUpdate linked to Cobalt Strike. The Python component, associated with the ZuRu malware family, harvested extensive data such as shell histories, SSH files, keychain contents, application data, and directory listings for exfiltration. Investigators also identified similarly trojanized macOS applications, including SecureCRT, Microsoft Remote Desktop, and Navicat, indicating a broader campaign targeting Mac users through cloned software download sites.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Patrick Wardle published an analysis of the macOS malware campaign dubbed OSX.ZuRu, detailing the fake iTerm2 site, malicious dylib injection, and second-stage payload delivery.
Security researcher Zhi (@CodeColorist) publicly reported the campaign and referenced an earlier Zhihu write-up describing the trojanized macOS software distribution activity.
The domain kaidingle.com was registered and later served multiple trojanized DMG packages, including iTerm, SecureCRT, and Navicat installers tied to the ZuRu campaign.
VirusTotal recorded multiple URLs on the campaign's second-stage server at 47.75.123.111 over this period, indicating active hosting of follow-on payloads and tools.
Trend Micro reported that a fake iTerm2 site distributed a trojanized app that loaded a malicious libcrypto.2.dylib, fetched g.py and GoogleUpdate, and stole extensive user and system data. The company also identified related trojanized macOS apps and infrastructure suggesting a broader campaign targeting Mac users.
Objective-See reported iTerm2.net appeared offline as of September 15, 2021, while Trend Micro later noted the same domain remained active as of that date, reflecting differing observations around the campaign infrastructure.
Apple revoked the 'Apple Distribution: Jun Bi (AQPZ6F3ASY)' certificate that had been used to sign the trojanized iTerm application.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 46 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.