logo

Why macOS malware like ZuRu still works, and how to stop it before it runs

ID: 447e6dee-dc13-59db-9cfd-fd89dfcb4efe

STIX ID: report--447e6dee-dc13-59db-9cfd-fd89dfcb4efe

Feed Name: ThreatLocker Blog

Threat Score
55/100

Date Published: 2025-08-12

Date Updated: 2026-05-01

...
...

A newly observed ZuRu macOS malware variant is being delivered by distributing a doctored Termius app signed with an ad-hoc signature; attackers rely on social engineering to get users to bypass Gatekeeper and manually allow the app to run. The piece details how the malware avoids advanced exploits, emphasizes user-driven execution as the primary failure point, and advocates prevention via application allowlisting and endpoint controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.