logo

HZ Rat backdoor for macOS attacks users of China’s DingTalk and WeChat

ID: 6badc2f6-1150-5dcf-abde-1dbd47355b43

STIX ID: report--6badc2f6-1150-5dcf-abde-1dbd47355b43

Feed Name: Securelist by Kaspersky

Threat Score
72/100

Date Published: 2024-08-27

Date Updated: 2026-04-29

Author: Sergey Puzan

...
...

Kaspersky researchers discovered a macOS variant of the HZ Rat backdoor (distributed via a trojanized OpenVPNConnect.pkg) that mirrors the Windows backdoor’s functionality but receives payloads as shell scripts. The backdoor establishes XOR-encrypted C2 communications (commonly on port 8081), supports command execution and file transfer primitives, harvests detailed system, WeChat and DingTalk user/organization data (stored in plaintext in app caches), and shows signs of targeted use and potential lateral movement via private IP addresses; the report includes multiple Mach-O hashes and active C2 IPs (mostly in China).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.