Fake Zoom installer uses .NET downloader to deliver Overlord RAT on macOS
ID: 6459be25-e7fd-5478-8a32-5e0c10041ae0
STIX ID: report--6459be25-e7fd-5478-8a32-5e0c10041ae0
Feed Name: Jamf Blog
Threat Score
Jamf Threat Labs identified a campaign where a fake Zoom installer (a self-contained .NET downloader) fetches and launches an Overlord RAT on macOS (with Windows-targeted payloads available), detailing obfuscation methods, staging behavior, persistence via LaunchAgents, rich remote access capabilities (keylogging, screen/audio/webcam capture, filesystem and process control), hardcoded C2 infrastructure, and multiple sample hashes and domains as IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
