Threat reportMalwareTL-2026-1950
Fake Zoom Installer Delivers Overlord RAT to macOS via .NET Downloader (ZoomMeetings)
Fake Zoom Installer Delivers Overlord RAT to macOS via .NET (TL-2026-1950) is a high-severity malware campaign, first published 2026-08-08. It is linked to a North Korea-nexus actor with low confidence, affects Apple macOS, maps to 18 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 21 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 18MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-1950
- Threat ID
- TL-2026-1950
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Nation-state nexus
- North Korea
- Motivation
- ESPIONAGE
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in Fake Zoom Installer Delivers Overlord RAT to macOS via .NET
Malware and tooling: FlexibleFerret, Overlord RAT, Garble
How Fake Zoom Installer Delivers Overlord RAT to macOS via .NET works
A fraudulent Zoom installer for macOS ARM64 (ZoomMeetings), built as a self-contained .NET 10 single-file Mach-O binary, backgrounds itself via nohup and deploys a Garble-obfuscated build of the open-source Overlord RAT from typosquatted zoom.com[.]kg/.lv infrastructure. Overlord provides keylogging, screen/webcam/microphone capture, full filesystem control, and LaunchAgent persistence that shares a naming convention with the DPRK-attributed FlexibleFerret family.
Jamf Threat Labs discovered a two-stage macOS (and Windows) malware campaign in which a fake Zoom installer named ZoomMeetings delivers the open-source Overlord remote access trojan. Stage 1 is a macOS ARM64 Mach-O binary built as a self-contained .NET 10 single-file application with the .NET runtime bundled internally -- the first time Jamf has observed .NET used as a macOS downloader. The outer Mach-O wrapper contains 34 embedded Windows PE-format DLLs (one spoofing legitimate Zoom Communications metadata, the rest standard .NET runtime libraries). Strings containing attacker infrastructure and payload URLs are hidden with a base64-plus-XOR (key 0x94) scheme and randomized identifiers, evading static AV detection. At runtime the downloader fingerprints OS/architecture via .NET RuntimeInformation APIs, generates a 6-character random token required by the C2 (requests without it return HTTP 401), writes a stage-2 payload to /tmp/ZoomMeetings, and launches it via a backgrounded nohup command so it survives termination of the parent process. It simultaneously fetches a legitimate Zoom installer as a decoy so the victim believes installation succeeded.
Stage 2 is a configured, Garble-obfuscated build of Overlord, a publicly available Go-based cross-platform RAT that connects to its controller over an encrypted WebSocket. This build's C2 is hardcoded to hub.zoom.com[.]kg:5173 with TLS certificate validation disabled (TLSInsecureSkipVerify: true); an optional Solana blockchain-based C2 resolver exists in the framework but is disabled here. Overlord's capabilities include keylogging via CGEventTap, screen/webcam/microphone capture, full filesystem control (browse/read/write/upload/download/move/rename/delete/chmod/zip), process management, multi-language remote script execution (bash, PowerShell, Python, Ruby, Node.js, Perl), a native/WASM plugin loader, self-update, and remote desktop streaming. A persistence variant, gated behind an OVERLORD_ENABLE_PERSISTENCE flag, copies itself to ~/Library/Application Support/Overlord/com.zoom and installs a LaunchAgent at ~/Library/LaunchAgents/com.zoom.plist (label com.zoom); on first execution it runs `ioreg -rd1 -c IOPlatformExpertDevice` to collect hardware UUID, serial number, and model identifier.
Infrastructure is built on typosquatted zoom.com domains under uncommon TLDs: cdn.zoom.com[.]kg (stage-2 host), hub.zoom.com[.]kg (primary C2, port 5173), and dash.zoom.com[.]kg all resolve to 18.204.152[.]241, while an alternate C2, hub.zoom.com[.]lv, resolves to 179.61.227[.]46. Queried against BeaconBeagle, neither 18.204.152.241 nor 179.61.227.46 returned an existing beacon/C2 correlation record (HTTP 404), indicating this infrastructure was not previously catalogued there.
Jamf explicitly states it does not attribute this campaign to a specific actor, but documents two notable overlaps: the LaunchAgent label and plist filename (com.zoom / com.zoom.plist) are identical to those used by FlexibleFerret, a DPRK-attributed macOS malware family tied to the 'Contagious Interview' fake-job-offer campaign (first documented by SentinelOne, Feb 2025); and the Overlord framework itself was previously used in UNK_DeadDrop, a cluster Proofpoint assesses as 'very likely North Korea-aligned' that ran a six-week (April-May 2026) developer-targeting phishing operation using Overlord-derived Go/Electron payloads for browser-credential and crypto-wallet theft -- though Jamf found no direct infrastructure overlap between UNK_DeadDrop and this specific fake-Zoom campaign. Taken together, the shared persistence naming convention and reuse of the same open-source RAT framework by a likely-DPRK cluster support a low-confidence, unconfirmed nation-state assessment rather than definitive attribution.
MITRE ATT&CK techniques used in TL-2026-1950
Collection
T1005 Data from Local System; T1113 Screen Capture; T1123 Audio Capture; T1125 Video Capture
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information
Credential Access
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Execution
T1059.001 PowerShell; T1059.004 Unix Shell; T1059.007 JavaScript; T1204.002 Malicious File
Persistence
Command and Control
Resource Development
Affected products and versions in Fake Zoom Installer Delivers Overlord RAT to macOS via .NET
Remediation for Fake Zoom Installer Delivers Overlord RAT to macOS via .NET
Immediate actions
- Block network traffic to hub.zoom.com[.]kg:5173, hub.zoom.com[.]lv, cdn.zoom.com[.]kg, and dash.zoom.com[.]kg, and to resolving IPs 18.204.152.241 and 179.61.227.46, at DNS/proxy/perimeter.
- Hunt for and remove ~/Library/LaunchAgents/com.zoom.plist (label com.zoom) and ~/Library/Application Support/Overlord/com.zoom on macOS endpoints.
- Isolate and forensically image any host that executed a binary named ZoomMeetings, ZoomInstallerFull, or zoomMacArm obtained outside the official zoom.us installer.
Workarounds
- Only download Zoom installers directly from zoom.us; verify code-signature/notarization before execution.
- Require explicit user review of Gatekeeper prompts and disable auto-execution of downloaded disk images/binaries.
Longer-term hardening
- Enforce Gatekeeper/notarization checks and block execution of unsigned or ad-hoc-signed 'Zoom' binaries downloaded outside official Zoom domains.
- Deploy EDR with behavioral detection for installer-named binaries that spawn backgrounded nohup children or open outbound WebSocket connections to non-standard high ports (e.g., 5173).
- Monitor for ioreg-based hardware-fingerprinting commands (ioreg -rd1 -c IOPlatformExpertDevice) spawned by recently-downloaded binaries as a pre-persistence indicator.
Timeline of Fake Zoom Installer Delivers Overlord RAT to macOS via .NET
- SentinelOne documents FlexibleFerret, a DPRK-attributed macOS malware family from the 'Contagious Interview' campaign, which later shares an identical com.zoom LaunchAgent label/plist filename with this campaign's Overlord persistence variant.
- Proofpoint's tracked window for the UNK_DeadDrop phishing campaign begins (reported window: April-May 2026); the likely North-Korea-aligned cluster deploys Go/Electron binaries derived from the open-source Overlord C2 framework against software developers.
- UNK_DeadDrop's roughly six-week phishing operation concludes, having sent 250+ emails to nearly 100 organizations in finance, cryptocurrency, education, and technology using Overlord-derived payloads.
- Proofpoint publishes 'Don't Fear the Repo,' assessing UNK_DeadDrop as very likely North Korea-aligned and detailing its use of the open-source Overlord framework.
- Independent tracker derp.ca records 20 IPs / 8 hostnames of active Overlord C2 infrastructure across US, German, French, Russian, and Dutch hosting during its Aug 2-8, 2026 observation window, overlapping this campaign's public disclosure.
- Cyberpress.org reports on the same campaign's cross-platform delivery, confirming Windows-targeted payload DLLs alongside the macOS ARM64 build.
- GBHackers republishes the findings, detailing the base64+XOR (key 0x94) string obfuscation and the hub.zoom.com[.]kg:5173 WebSocket C2 with TLS verification disabled.
- Jamf Threat Labs discovers and publishes analysis of the fake Zoom installer campaign: the ZoomMeetings .NET 10 downloader and a Garble-obfuscated Overlord RAT agent targeting macOS (ARM64/Intel) and Windows.
Sources cited for Fake Zoom Installer Delivers Overlord RAT to macOS via .NET
- Fake Zoom Installer Uses .NET Downloader to Deploy Overlord RAT on macOS
- Fake Zoom Installer Delivers Overlord RAT on macOS
- Fake Zoom Installer Delivers Overlord RAT to macOS and Windows Systems
- Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency
- macOS FlexibleFerret | Further Variants of DPRK Malware Family Unearthed
- Overlord Malware Profile & 7d C2 Tracker
- Overlord RAT - Open Source C2 Framework (GitHub)
Detection coverage for TL-2026-1950
As of 2026-08-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1950 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.