EXECUTIVE SUMMARY
A Remote Access Trojan (RAT) known for targeting Windows devices has adapted to infiltrate macOS systems. HZ RAT, a malware that disguises itself as legitimate software to deceive users, gains control over infected systems by establishing a connection with a command-and-control (C2) server operated by cybercriminals. This update signals an expanded threat scope as the RAT now actively targets Mac users, putting them at risk for full remote access exploitation.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A Remote Access Trojan (RAT) known for targeting Windows devices has adapted to infiltrate macOS systems. HZ RAT, a malware that disguises itself as legitimate software to deceive users, gains control over infected systems by establishing a connection with a command-and-control (C2) server operated by cybercriminals. This update signals an expanded threat scope as the RAT now actively targets Mac users, putting them at risk for full remote access exploitation.[emaillocker id="1283"]
Once deployed, HZ RAT gives attackers extensive administrative control over infected macOS devices, enabling them to execute commands, record keystrokes, and take screenshots. Additionally, the malware gathers sensitive data from applications commonly used in China, such as WeChat and DingTalk, as well as usernames and website information from Google Password Manager. While it does not directly extract passwords from Google Password Manager, it is speculated that attackers may combine this data with stolen credentials from dark web marketplaces. The malware is reportedly distributed through fake Google Ads, spoofed websites, or watering hole attacks, though the exact vector remains unconfirmed. Detection rates for this malware are low, posing a significant challenge for security defenses.
HZ RAT presents a persistent and stealthy threat for macOS users, with capabilities that allow threat actors to spy on and exfiltrate valuable data. Due to its low detection profile and sophisticated C2 communication, this RAT has largely evaded security systems and could remain undetected on infected devices for extended periods. Users are strongly advised to only download applications from official and verified sources like the Apple App Store to mitigate the risk of infection and exposure.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| T1189 | Drive-by Compromise | |
| Execution | T1059 | Command and Scripting Interpreter |
| Persistence | T1547 | Boot or Logon Autostart Execution |
| Privilege Escalation | T1548 | Abuse Elevation Control Mechanism |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| T1036 | Masquerading | |
| Discovery | T1082 | System Information Discovery |
| T1046 | Network Service Discovery | |
| T1010 | Application Window Discovery | |
| T1083 | File and Directory Discovery | |
| Collection | T1113 | Screen Capture |
| T1213 | Data from Information Repositories | |
| Command and Control | T1071 | Application Layer Protocol |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| T1020 | Automated Exfiltration | |
| Impact | T1565 | Data Manipulation |
| T1490 | Inhibit System Recovery |
REFERENCES:
The following reports contain further technical details:
https://cybersecuritynews.com/macos-malware-control-device-remotely/