logo

Fake Zoom Installer Uses .NET Downloader to Deploy Overlord RAT on macOS

ID: 057381eb-2b52-5cef-8e09-103d3f06a9df

STIX ID: report--057381eb-2b52-5cef-8e09-103d3f06a9df

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-08-08

Date Updated: 2026-08-10

Author: Eswar

...
...

**Executive summary:** Jamf documented a cross-platform campaign that disguises a .NET single-file Zoom installer to deploy the Overlord RAT on macOS and Windows, using heavy obfuscation, hardcoded C2 (hub.zoom.com.kg:5173), disabled TLS verification, and optional LaunchAgent persistence; the report provides multiple IOCs (domains, IPs, file paths, and SHA-256 hashes) and recommends enabling threat prevention and web protection to mitigate similar attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.