Threat reportMalwareTL-2026-1950

Fake Zoom Installer Delivers Overlord RAT to macOS via .NET Downloader (ZoomMeetings)

highACTIVE

Fake Zoom Installer Delivers Overlord RAT to macOS via .NET (TL-2026-1950) is a high-severity malware campaign, first published 2026-08-08. It is linked to a North Korea-nexus actor with low confidence, affects Apple macOS, maps to 18 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 21 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
21Indicators of compromise

Key facts for TL-2026-1950

Threat ID
TL-2026-1950
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Nation-state nexus
North Korea
Motivation
ESPIONAGE
Detection rules
9
Indicators of compromise
21

Malware and tooling in Fake Zoom Installer Delivers Overlord RAT to macOS via .NET

Malware and tooling: FlexibleFerret, Overlord RAT, Garble

How Fake Zoom Installer Delivers Overlord RAT to macOS via .NET works

A fraudulent Zoom installer for macOS ARM64 (ZoomMeetings), built as a self-contained .NET 10 single-file Mach-O binary, backgrounds itself via nohup and deploys a Garble-obfuscated build of the open-source Overlord RAT from typosquatted zoom.com[.]kg/.lv infrastructure. Overlord provides keylogging, screen/webcam/microphone capture, full filesystem control, and LaunchAgent persistence that shares a naming convention with the DPRK-attributed FlexibleFerret family.

Jamf Threat Labs discovered a two-stage macOS (and Windows) malware campaign in which a fake Zoom installer named ZoomMeetings delivers the open-source Overlord remote access trojan. Stage 1 is a macOS ARM64 Mach-O binary built as a self-contained .NET 10 single-file application with the .NET runtime bundled internally -- the first time Jamf has observed .NET used as a macOS downloader. The outer Mach-O wrapper contains 34 embedded Windows PE-format DLLs (one spoofing legitimate Zoom Communications metadata, the rest standard .NET runtime libraries). Strings containing attacker infrastructure and payload URLs are hidden with a base64-plus-XOR (key 0x94) scheme and randomized identifiers, evading static AV detection. At runtime the downloader fingerprints OS/architecture via .NET RuntimeInformation APIs, generates a 6-character random token required by the C2 (requests without it return HTTP 401), writes a stage-2 payload to /tmp/ZoomMeetings, and launches it via a backgrounded nohup command so it survives termination of the parent process. It simultaneously fetches a legitimate Zoom installer as a decoy so the victim believes installation succeeded.

Stage 2 is a configured, Garble-obfuscated build of Overlord, a publicly available Go-based cross-platform RAT that connects to its controller over an encrypted WebSocket. This build's C2 is hardcoded to hub.zoom.com[.]kg:5173 with TLS certificate validation disabled (TLSInsecureSkipVerify: true); an optional Solana blockchain-based C2 resolver exists in the framework but is disabled here. Overlord's capabilities include keylogging via CGEventTap, screen/webcam/microphone capture, full filesystem control (browse/read/write/upload/download/move/rename/delete/chmod/zip), process management, multi-language remote script execution (bash, PowerShell, Python, Ruby, Node.js, Perl), a native/WASM plugin loader, self-update, and remote desktop streaming. A persistence variant, gated behind an OVERLORD_ENABLE_PERSISTENCE flag, copies itself to ~/Library/Application Support/Overlord/com.zoom and installs a LaunchAgent at ~/Library/LaunchAgents/com.zoom.plist (label com.zoom); on first execution it runs `ioreg -rd1 -c IOPlatformExpertDevice` to collect hardware UUID, serial number, and model identifier.

Infrastructure is built on typosquatted zoom.com domains under uncommon TLDs: cdn.zoom.com[.]kg (stage-2 host), hub.zoom.com[.]kg (primary C2, port 5173), and dash.zoom.com[.]kg all resolve to 18.204.152[.]241, while an alternate C2, hub.zoom.com[.]lv, resolves to 179.61.227[.]46. Queried against BeaconBeagle, neither 18.204.152.241 nor 179.61.227.46 returned an existing beacon/C2 correlation record (HTTP 404), indicating this infrastructure was not previously catalogued there.

Jamf explicitly states it does not attribute this campaign to a specific actor, but documents two notable overlaps: the LaunchAgent label and plist filename (com.zoom / com.zoom.plist) are identical to those used by FlexibleFerret, a DPRK-attributed macOS malware family tied to the 'Contagious Interview' fake-job-offer campaign (first documented by SentinelOne, Feb 2025); and the Overlord framework itself was previously used in UNK_DeadDrop, a cluster Proofpoint assesses as 'very likely North Korea-aligned' that ran a six-week (April-May 2026) developer-targeting phishing operation using Overlord-derived Go/Electron payloads for browser-credential and crypto-wallet theft -- though Jamf found no direct infrastructure overlap between UNK_DeadDrop and this specific fake-Zoom campaign. Taken together, the shared persistence naming convention and reuse of the same open-source RAT framework by a likely-DPRK cluster support a low-confidence, unconfirmed nation-state assessment rather than definitive attribution.

MITRE ATT&CK techniques used in TL-2026-1950

Collection

T1005 Data from Local System; T1113 Screen Capture; T1123 Audio Capture; T1125 Video Capture

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information

Credential Access

T1056.001 Keylogging

Discovery

T1057 Process Discovery; T1082 System Information Discovery

Execution

T1059.001 PowerShell; T1059.004 Unix Shell; T1059.007 JavaScript; T1204.002 Malicious File

Persistence

T1543.001 Launch Agent

Command and Control

T1573 Encrypted Channel

Resource Development

T1583.001 Domains; T1587.001 Malware

Affected products and versions in Fake Zoom Installer Delivers Overlord RAT to macOS via .NET

  • Apple — macOS
    Vulnerable versions: macOS on Apple Silicon (ARM64); Intel build also referenced
  • Microsoft — Windows
    Vulnerable versions: Windows x64 (cross-platform Overlord payload)

Remediation for Fake Zoom Installer Delivers Overlord RAT to macOS via .NET

Immediate actions

  • Block network traffic to hub.zoom.com[.]kg:5173, hub.zoom.com[.]lv, cdn.zoom.com[.]kg, and dash.zoom.com[.]kg, and to resolving IPs 18.204.152.241 and 179.61.227.46, at DNS/proxy/perimeter.
  • Hunt for and remove ~/Library/LaunchAgents/com.zoom.plist (label com.zoom) and ~/Library/Application Support/Overlord/com.zoom on macOS endpoints.
  • Isolate and forensically image any host that executed a binary named ZoomMeetings, ZoomInstallerFull, or zoomMacArm obtained outside the official zoom.us installer.

Workarounds

  • Only download Zoom installers directly from zoom.us; verify code-signature/notarization before execution.
  • Require explicit user review of Gatekeeper prompts and disable auto-execution of downloaded disk images/binaries.

Longer-term hardening

  • Enforce Gatekeeper/notarization checks and block execution of unsigned or ad-hoc-signed 'Zoom' binaries downloaded outside official Zoom domains.
  • Deploy EDR with behavioral detection for installer-named binaries that spawn backgrounded nohup children or open outbound WebSocket connections to non-standard high ports (e.g., 5173).
  • Monitor for ioreg-based hardware-fingerprinting commands (ioreg -rd1 -c IOPlatformExpertDevice) spawned by recently-downloaded binaries as a pre-persistence indicator.

Timeline of Fake Zoom Installer Delivers Overlord RAT to macOS via .NET

  • SentinelOne documents FlexibleFerret, a DPRK-attributed macOS malware family from the 'Contagious Interview' campaign, which later shares an identical com.zoom LaunchAgent label/plist filename with this campaign's Overlord persistence variant.
  • Proofpoint's tracked window for the UNK_DeadDrop phishing campaign begins (reported window: April-May 2026); the likely North-Korea-aligned cluster deploys Go/Electron binaries derived from the open-source Overlord C2 framework against software developers.
  • UNK_DeadDrop's roughly six-week phishing operation concludes, having sent 250+ emails to nearly 100 organizations in finance, cryptocurrency, education, and technology using Overlord-derived payloads.
  • Proofpoint publishes 'Don't Fear the Repo,' assessing UNK_DeadDrop as very likely North Korea-aligned and detailing its use of the open-source Overlord framework.
  • Independent tracker derp.ca records 20 IPs / 8 hostnames of active Overlord C2 infrastructure across US, German, French, Russian, and Dutch hosting during its Aug 2-8, 2026 observation window, overlapping this campaign's public disclosure.
  • Cyberpress.org reports on the same campaign's cross-platform delivery, confirming Windows-targeted payload DLLs alongside the macOS ARM64 build.
  • GBHackers republishes the findings, detailing the base64+XOR (key 0x94) string obfuscation and the hub.zoom.com[.]kg:5173 WebSocket C2 with TLS verification disabled.
  • Jamf Threat Labs discovers and publishes analysis of the fake Zoom installer campaign: the ZoomMeetings .NET 10 downloader and a Garble-obfuscated Overlord RAT agent targeting macOS (ARM64/Intel) and Windows.

Sources cited for Fake Zoom Installer Delivers Overlord RAT to macOS via .NET

Detection coverage for TL-2026-1950

As of 2026-08-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1950 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
21 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats