Sunday, September 13, 2026

Weaponized Termius App Delivers Latest ZuRu Malware to macOS Users

A sophisticated variant of the macOS.ZuRu malware, first identified by a Chinese blogger in July 2021, has resurfaced with a new method of attack targeting macOS users through a trojanized version of the popular cross-platform SSH client Termius.

Initially spread via poisoned Baidu search results for tools like iTerm2, SecureCRT, and Microsoft Remote Desktop for Mac, ZuRu has consistently preyed on users of backend and remote connection utilities.

A New Chapter in macOS.ZuRu’s Evolution

The latest sample, discovered in late May 2025 through social media reports, showcases an evolved delivery mechanism and a modified Khepri C2 framework for post-infection control, marking a significant shift in the malware’s tactics while maintaining its focus on evading detection.

The malware is distributed through a .dmg disk image containing a hacked Termius.app, inflated from its legitimate size of 225MB to 248MB due to embedded malicious binaries.

Unlike prior ZuRu variants that relied on Dylib injection to modify the main executable, this version embeds two additional executables within the Termius Helper.app bundle.

The legitimate Termius Helper binary is renamed and replaced with a 25MB Mach-O file that launches both a malware loader named “.localized” and the renamed original helper to maintain normal app functionality.

The “.localized” loader retrieves a Khepri C2 beacon from download.termius[.]info, decrypts it using a hardcoded key “my_secret_key,” and installs it at /tmp/.fseventsd.

ZuRu Malware
Khepri C2 task list

Technical Breakdown of the Trojanized Application

According to the Report, Persistence is achieved via a malicious LaunchDaemon plist labeled com.apple.xssooxxagent, written to /Library/LaunchDaemons/, ensuring hourly execution of the malware from /Users/Shared/.

The loader also implements an update mechanism by verifying the payload’s MD5 hash against a remote value, downloading newer versions if discrepancies are detected.

This latest decryption routine, while still using XOR combined with addition and subtraction, replaces the older single-byte key with a 13-byte string, adding a layer of obfuscation to thwart automated analysis.

The Khepri beacon, a customized version of the open-source C2 framework, is a universal Mach-O binary requiring macOS Sonoma 14.1 or later, and it communicates with its command-and-control server at ctl01.termius[.]fun (resolving to 47.238.28.21) over port 53, mimicking DNS traffic.

Its capabilities include file transfer, system reconnaissance, and command execution, making it a potent tool for attackers.

Despite evolving techniques, such as shifting from Dylib injection to helper app trojanization, the threat actors reuse familiar patterns in domain naming and persistence methods, indicating sustained success in environments lacking robust endpoint protection.

SentinelOne Singularity effectively detects and blocks this threat, while organizations without such defenses are urged to monitor for the indicators of compromise listed below.

Indicators of Compromise

TypeIndicatorDescription
File Path/Library/LaunchDaemons/com.apple.xssooxxagent.plistPersistence plist file
File Path/Users/Shared/com.apple.xssooxxagentMalware executable location
File Path/tmp/.fseventsdKhepri C2 Beacon location
SHA-1a7a9b0f8cc1c89f5c195af74ce3add74733b15c0.fseventsd (Khepri C2 Beacon)
SHA-1de8aca685871ade8a75e4614ada219025e2d6fd7Termius9.5.0.dmg (Trojan Image)
Networkhttp://download.termius[.]info/bn.log.encPayload download URL
Networkctl01.termius[.]funC2 server domain

Stay Updated on Daily Cybersecurity News. Follow us on Google News, LinkedIn, and X.

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News