Threat Advisory

New macOS HZ RAT Malware Lets Attackers Control Device Remotely

Threat: Malware
Targeted Region: China
Threat Actor Region: China
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A Remote Access Trojan (RAT) known for targeting Windows devices has adapted to infiltrate macOS systems. HZ RAT, a malware that disguises itself as legitimate software to deceive users, gains control over infected systems by establishing a connection with a command-and-control (C2) server operated by cybercriminals. This update signals an expanded threat scope as the RAT now actively targets Mac users, putting them at risk for full remote access exploitation.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A Remote Access Trojan (RAT) known for targeting Windows devices has adapted to infiltrate macOS systems. HZ RAT, a malware that disguises itself as legitimate software to deceive users, gains control over infected systems by establishing a connection with a command-and-control (C2) server operated by cybercriminals. This update signals an expanded threat scope as the RAT now actively targets Mac users, putting them at risk for full remote access exploitation.[emaillocker id="1283"]

Once deployed, HZ RAT gives attackers extensive administrative control over infected macOS devices, enabling them to execute commands, record keystrokes, and take screenshots. Additionally, the malware gathers sensitive data from applications commonly used in China, such as WeChat and DingTalk, as well as usernames and website information from Google Password Manager. While it does not directly extract passwords from Google Password Manager, it is speculated that attackers may combine this data with stolen credentials from dark web marketplaces. The malware is reportedly distributed through fake Google Ads, spoofed websites, or watering hole attacks, though the exact vector remains unconfirmed. Detection rates for this malware are low, posing a significant challenge for security defenses.

HZ RAT presents a persistent and stealthy threat for macOS users, with capabilities that allow threat actors to spy on and exfiltrate valuable data. Due to its low detection profile and sophisticated C2 communication, this RAT has largely evaded security systems and could remain undetected on infected devices for extended periods. Users are strongly advised to only download applications from official and verified sources like the Apple App Store to mitigate the risk of infection and exposure.

THREAT PROFILE:

Tactic Technique Id Technique
 Initial Access  T1566 Phishing
 T1189 Drive-by Compromise
Execution T1059 Command and Scripting Interpreter
Persistence  T1547 Boot or Logon Autostart Execution
Privilege Escalation T1548 Abuse Elevation Control Mechanism
Defense Evasion T1027 Obfuscated Files or Information
T1036 Masquerading
Discovery  T1082 System Information Discovery
 T1046 Network Service Discovery
T1010 Application Window Discovery
 T1083 File and Directory Discovery
Collection T1113 Screen Capture
T1213 Data from Information Repositories
Command and Control T1071 Application Layer Protocol
 Exfiltration T1041 Exfiltration Over C2 Channel
 T1020 Automated Exfiltration
 Impact T1565 Data Manipulation
T1490 Inhibit System Recovery

REFERENCES:

The following reports contain further technical details:
https://cybersecuritynews.com/macos-malware-control-device-remotely/

[/emaillocker]
crossmenu