Fake Zoom Installer Uses .NET Downloader to Deploy Overlord RAT on macOS
ID: 057381eb-2b52-5cef-8e09-103d3f06a9df
STIX ID: report--057381eb-2b52-5cef-8e09-103d3f06a9df
Feed Name: GBHackers
Threat Score
**Executive summary:** Jamf documented a cross-platform campaign that disguises a .NET single-file Zoom installer to deploy the Overlord RAT on macOS and Windows, using heavy obfuscation, hardcoded C2 (hub.zoom.com.kg:5173), disabled TLS verification, and optional LaunchAgent persistence; the report provides multiple IOCs (domains, IPs, file paths, and SHA-256 hashes) and recommends enabling threat prevention and web protection to mitigate similar attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
