216.73.216.36

macOS.ZuRu Resurfaces | Modified Khepri C2 Hides Inside Doctored Termius App

· Published 10/07/2025 17:53 · Modified 13/07/2025 10:47

Export JSON

Essential information

Published
10/07/2025 17:53
Modified
13/07/2025 10:47
Tags
2025-07-10 backdoor c2 beacon khepri khepri c2 macos macos.zuru persistence termius trojan zuru
Related entities
4 observables, 7 techniques (mitre)

Description

A new variant of malware has been discovered, targeting users through a trojanized version of the app. This , initially noted in 2021, now uses a modified framework for post-infection operations. The malware is delivered via a .dmg disk image containing a hacked version of .app. It adds two executables to the embedded Helper.app and uses a new method to trojanize legitimate applications. The malware installs via a LaunchDaemon and includes an md5 updater mechanism. The payload obtained from the C2 is a modified beacon with capabilities for file transfer, system reconnaissance, and command execution. The threat actor continues to target developers and IT professionals, adapting their techniques to evade detection.

External references