macOS.ZuRu Resurfaces | Modified Khepri C2 Hides Inside Doctored Termius App
Essential information
- Published
- 10/07/2025 17:53
- Modified
- 13/07/2025 10:47
- Tags
- 2025-07-10 backdoor c2 beacon khepri khepri c2 macos macos.zuru persistence termius trojan zuru
- Related entities
- 4 observables, 7 techniques (mitre)
Description
A new variant of macOS.ZuRu malware has been discovered, targeting users through a trojanized version of the Termius app. This backdoor, initially noted in 2021, now uses a modified Khepri C2 framework for post-infection operations. The malware is delivered via a .dmg disk image containing a hacked version of Termius.app. It adds two executables to the embedded Termius Helper.app and uses a new method to trojanize legitimate applications. The malware installs persistence via a LaunchDaemon and includes an md5 updater mechanism. The payload obtained from the C2 is a modified Khepri beacon with capabilities for file transfer, system reconnaissance, and command execution. The threat actor continues to target developers and IT professionals, adapting their techniques to evade detection.