logo

Experts Warn of macOS Backdoor Hidden in Pirated Versions of Popular Software

ID: 8ae4274e-311d-523e-a0fe-ccb6a1bd8b11

STIX ID: report--8ae4274e-311d-523e-a0fe-ccb6a1bd8b11

Feed Name: The Hacker News

Threat Score
68/100

Date Published: 2024-01-19

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** Pirated macOS applications hosted on Chinese websites have been trojanized to include a dropper that installs a Khepri-based backdoor (/tmp/.test) and a downloader (written to /Users/Shared/.fseventsd) that creates a LaunchAgent to achieve persistence and fetch additional payloads; affected installers include Navicat, UltraEdit, FinalShell, SecureCRT, and Microsoft Remote Desktop, and the activity shows similarities to the ZuRu family.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.