HZ Rat backdoor for macOS attacks users of China’s DingTalk and WeChat
ID: 6badc2f6-1150-5dcf-abde-1dbd47355b43
STIX ID: report--6badc2f6-1150-5dcf-abde-1dbd47355b43
Feed Name: Securelist by Kaspersky
Kaspersky researchers discovered a macOS variant of the HZ Rat backdoor (distributed via a trojanized OpenVPNConnect.pkg) that mirrors the Windows backdoor’s functionality but receives payloads as shell scripts. The backdoor establishes XOR-encrypted C2 communications (commonly on port 8081), supports command execution and file transfer primitives, harvests detailed system, WeChat and DingTalk user/organization data (stored in plaintext in app caches), and shows signs of targeted use and potential lateral movement via private IP addresses; the report includes multiple Mach-O hashes and active C2 IPs (mostly in China).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
