logo

Fake Zoom installer uses .NET downloader to deliver Overlord RAT on macOS

ID: 6459be25-e7fd-5478-8a32-5e0c10041ae0

STIX ID: report--6459be25-e7fd-5478-8a32-5e0c10041ae0

Feed Name: Jamf Blog

Threat Score
75/100

Date Published: 2026-08-04

Date Updated: 2026-08-06

...
...

Jamf Threat Labs identified a campaign where a fake Zoom installer (a self-contained .NET downloader) fetches and launches an Overlord RAT on macOS (with Windows-targeted payloads available), detailing obfuscation methods, staging behavior, persistence via LaunchAgents, rich remote access capabilities (keylogging, screen/audio/webcam capture, filesystem and process control), hardcoded C2 infrastructure, and multiple sample hashes and domains as IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.