OSX.ZuRu trojanizes macOS apps via Baidu ads
A macOS trojan called OSX.ZuRu is spread through fake sponsored Baidu search results for iTerm2 and other apps, dropping a Cobalt Strike backdoor and stealing system data.
Researchers identified a malvertising campaign delivering OSX.ZuRu, a macOS backdoor distributed through cloned websites (e.g., iTerm2.net) promoted via sponsored Baidu search results. Victims searching for legitimate tools like iTerm2 were served malicious sponsored links leading to trojanized disk images signed with a now-revoked Apple developer certificate. The trojanized application appears functionally identical to the legitimate app but loads a malicious dylib (libcrypto.2.dylib) at launch via a hijacked LC_LOAD_DYLIB entry, which executes automatically through Objective-C's +load method.
Once triggered, the malware beacons to a remote server (apps.mzstatics.com) using the infected machine's serial number as a unique identifier, then downloads and executes two second-stage payloads from 47.75.123.111: a Python script (g.py) that surveys the system (OS version, keychain, bash history, installed apps) and exfiltrates the data, and a UPX-packed Mach-O binary (GoogleUpdate) that connects to 47.75.96.198, an IP flagged on VirusTotal as an active Cobalt Strike C2 server. This grants attackers a full post-exploitation foothold on compromised macOS systems.
The researcher who first identified the campaign noted the scale was 'massive,' with additional trojanized applications discovered beyond iTerm2, including SecureCRT, Navicat15 (Chinese version), and a Microsoft Remote Desktop client, suggesting a broader supply-chain-style trojanizing operation targeting macOS users, likely concentrated in Chinese-speaking regions given the use of Baidu and Chinese-language artifacts. Apple has since revoked the abused code-signing certificate, and Baidu has reportedly removed the malicious sponsored links, but additional trojanized samples may remain undetected as none of the analyzed files were flagged by antivirus engines on VirusTotal at time of writing.
Mentioned in this report
Source reporting: https://objective-see.org/blog/blog_0x66.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free