HomeSecurityNew MacOS HZ RAT allows remote device control

New MacOS HZ RAT allows remote device control

A remote access malware, HZ RAT , that has been attacking Windows- based devices since at least 2020, was recently upgraded to target MacOS as well.

See also: Zero-Click vulnerability in macOS Calendar allows malicious actions

MacOS malware HZ RAT

Typically, a RAT is a type of malware that an attacker uses to remotely take control of a target computer and gain full administrator.

RATs are often delivered to their target as attachments, via phishing emails, or downloaded along with applications that appear to be legitimate user requests, such as video games.

On September 5, Intego announced that it had released a new version of the HZ RAT designed to attack macOS environments. According to previous reports about the HZ RAT, China is the country of origin of the malware, although Intego does not disclose performance information.

HZ RAT, a recent addition to the MacOS malware family, is a tool that gives the attacker full remote administration access. This RAT first appeared on Windows computers in 2022 and has now arrived on Mac.

As stated in the Moonlock, HZ RAT can spy on users and steal data, but it is not a legitimate thief due to its ingenuity and persistence. As a trojan , the malware provides the attacker with full remote administrator capabilities.

After the malware is installed, it establishes a connection to a command and control server to receive further instructions. This means that the attacker has the ability to upload and export files to their server, write arbitrary files to the system, and execute scripts and PowerShell from remote locations.

See also: Cthulhu Stealer: New info-stealer malware targets MacOS

New MacOS HZ RAT allows remote device control

It is believed that “ water hole ” attacks , fraudulent Google ads, and website spoofing could be used to spread the new MacOS malware, HZ RAT.

From a compromised Mac, malware can collect the following information:

  • Local IP address
  • Bluetooth device data
  • Wi-Fi networks and wireless network adapter data
  • Information about the network the device is connected to
  • Material specifications
  • Data storage information
  • List of applications on the device
  • Information from WeChat
  • User and organization data from DingTalk
  • Username and websites from Google Password Manager

Although the malware does not harvest passwords from Google Password Manager, it is suspected that hackers are leveraging leaks of stolen passwords obtained on the Dark Web to combine them with username and other data extracted by the malware.

The actual purpose of the HZ RAT for MacOS is unknown, other than data collection. Even more worrying is that security providers have been unable to detect this ransomware.

See also: TodoSwift: New macOS malware – Is it linked to North Korean hackers?

Malware refers to any software that is intentionally designed to harm a computer, server, client, or computer network. It includes a variety of harmful programs, such as viruses, worms, trojans, ransomware, and spyware, each with its own method of penetration and damage. Malware is often used by cybercriminals to steal sensitive data, disrupt operations, or gain unauthorized access to systems. Protecting against malware includes using up-to-date antivirus software, implementing strong security protocols, and staying up-to-date on the latest threats in the cybersecurity landscape.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS