s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.hz_rat

📛 Threat Title

Malware family: HZ RAT

Category: HZ RAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.hz_rat`. Printable name: HZ RAT.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    A Remote Access Trojan ( RAT ) known for targeting Windows devices has adapted to infiltrate macOS systems. HZ RAT , a malware that disguises itself as legitimate software to deceive users, gains control over infected systems by establishing a connection with a command-and-control (C2) server operated by cybercriminals.

  • web:cybersecuritynews.com

    According to prior reports on HZ RAT , China is the origin host of malware , even though Intego does not disclose attribution information. HZ RAT , a recent addition to the Mac malware family , is a tool that grants an attacker complete remote administration access. This RAT first surfaced on Windows PCs in 2022, and it has now made its way to the Mac.

  • web:hivepro.com

    HZ RAT is a sophisticated backdoor targeting macOS systems, particularly those using DingTalk and WeChat. This macOS variant mirrors its Windows predecessor but delivers payloads as shell scripts from the attacker's server. The malware's infrastructure includes multiple C2 servers, primarily in China, with some located in the US and the Netherlands.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the HZ RAT malware family including references, samples and yara signatures.

  • web:moonlock.com

    HZ RAT pivots from targeting Windows devices to Mac users On September 5, Intego reported that a new version of HZ RAT , built to breach macOS environments, is being distributed in the wild. While Intego does not provide attribution details, historical reports on HZ RAT point to China as the origin host for this malware .

  • web:securelist.com

    Kaspersky experts discovered a macOS version of the HZ Rat backdoor, which collects user data from WeChat and DingTalk messengers.

  • web:thehackernews.com

    Discover how the HZ RAT backdoor is now targeting MacOS users of Chinese messaging apps, posing a new cybersecurity threat to Apple devices.

  • web:www.broadcom.com

    HZ is a remote access trojan ( RAT ) variant distributed either as an embedded self-extracting .zip archive or a .rtf document attached to malspam. The distribution chain with the use of .rtf attachments is known to leverage exploit of a relatively old Equation Editor vulnerability - CVE-2017-11882.

  • web:www.intego.com

    HZ RAT is brand-new macOS malware that gives remote attackers complete control of an infected Mac. Here is everything you need to know to stay protected from this threat.

  • web:www.securemac.com

    HZ RAT is a Remote Access Trojan ( RAT ) that is capable of granting remote attackers complete control of an infected Mac. HZ RAT Threat Removal MacScan can detect and remove HZ RAT Hybrid Threat from your system, as well as provide protection against other security and privacy threats. A 30-day trial is available to scan your system for this threat.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.