# Fake Zoom Installer Delivers Overlord RAT to macOS via .NET Downloader (ZoomMeetings)

> A fraudulent Zoom installer for macOS ARM64 (ZoomMeetings), built as a self-contained .NET 10 single-file Mach-O binary, backgrounds itself via nohup and deploys a Garble-obfuscated build of the open-source Overlord RAT from typosquatted zoom.com[.]kg/.lv infrastructure. Overlord provides keylogging, screen/webcam/microphone capture, full filesystem control, and LaunchAgent persistence that shares a naming convention with the DPRK-attributed FlexibleFerret family.

- **Published:** 2026-08-08T00:00:00Z
- **Last reviewed:** 2026-08-08T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1950
- **ID:** TL-2026-1950
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Jamf Threat Labs discovered a two-stage macOS (and Windows) malware campaign in which a fake Zoom installer named ZoomMeetings delivers the open-source Overlord remote access trojan. Stage 1 is a macOS ARM64 Mach-O binary built as a self-contained .NET 10 single-file application with the .NET runtime bundled internally -- the first time Jamf has observed .NET used as a macOS downloader. The outer Mach-O wrapper contains 34 embedded Windows PE-format DLLs (one spoofing legitimate Zoom Communications metadata, the rest standard .NET runtime libraries). Strings containing attacker infrastructure and payload URLs are hidden with a base64-plus-XOR (key 0x94) scheme and randomized identifiers, evading static AV detection. At runtime the downloader fingerprints OS/architecture via .NET RuntimeInformation APIs, generates a 6-character random token required by the C2 (requests without it return HTTP 401), writes a stage-2 payload to /tmp/ZoomMeetings, and launches it via a backgrounded nohup command so it survives termination of the parent process. It simultaneously fetches a legitimate Zoom installer as a decoy so the victim believes installation succeeded.

Stage 2 is a configured, Garble-obfuscated build of Overlord, a publicly available Go-based cross-platform RAT that connects to its controller over an encrypted WebSocket. This build's C2 is hardcoded to hub.zoom.com[.]kg:5173 with TLS certificate validation disabled (TLSInsecureSkipVerify: true); an optional Solana blockchain-based C2 resolver exists in the framework but is disabled here. Overlord's capabilities include keylogging via CGEventTap, screen/webcam/microphone capture, full filesystem control (browse/read/write/upload/download/move/rename/delete/chmod/zip), process management, multi-language remote script execution (bash, PowerShell, Python, Ruby, Node.js, Perl), a native/WASM plugin loader, self-update, and remote desktop streaming. A persistence variant, gated behind an OVERLORD_ENABLE_PERSISTENCE flag, copies itself to ~/Library/Application Support/Overlord/com.zoom and installs a LaunchAgent at ~/Library/LaunchAgents/com.zoom.plist (label com.zoom); on first execution it runs `ioreg -rd1 -c IOPlatformExpertDevice` to collect hardware UUID, serial number, and model identifier.

Infrastructure is built on typosquatted zoom.com domains under uncommon TLDs: cdn.zoom.com[.]kg (stage-2 host), hub.zoom.com[.]kg (primary C2, port 5173), and dash.zoom.com[.]kg all resolve to 18.204.152[.]241, while an alternate C2, hub.zoom.com[.]lv, resolves to 179.61.227[.]46. Queried against BeaconBeagle, neither 18.204.152.241 nor 179.61.227.46 returned an existing beacon/C2 correlation record (HTTP 404), indicating this infrastructure was not previously catalogued there.

Jamf explicitly states it does not attribute this campaign to a specific actor, but documents two notable overlaps: the LaunchAgent label and plist filename (com.zoom / com.zoom.plist) are identical to those used by FlexibleFerret, a DPRK-attributed macOS malware family tied to the 'Contagious Interview' fake-job-offer campaign (first documented by SentinelOne, Feb 2025); and the Overlord framework itself was previously used in UNK_DeadDrop, a cluster Proofpoint assesses as 'very likely North Korea-aligned' that ran a six-week (April-May 2026) developer-targeting phishing operation using Overlord-derived Go/Electron payloads for browser-credential and crypto-wallet theft -- though Jamf found no direct infrastructure overlap between UNK_DeadDrop and this specific fake-Zoom campaign. Taken together, the shared persistence naming convention and reuse of the same open-source RAT framework by a likely-DPRK cluster support a low-confidence, unconfirmed nation-state assessment rather than definitive attribution.

## MITRE ATT&CK

- T1583.001 Domains
- T1587.001 Malware
- T1204.002 Malicious File
- T1059.004 Unix Shell
- T1059.001 PowerShell
- T1059.007 JavaScript
- T1543.001 Launch Agent
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1036.005 Match Legitimate Resource Name or Location
- T1056.001 Keylogging
- T1082 System Information Discovery
- T1057 Process Discovery
- T1113 Screen Capture
- T1123 Audio Capture
- T1125 Video Capture
- T1005 Data from Local System
- T1573 Encrypted Channel

## Sources

- [Fake Zoom Installer Uses .NET Downloader to Deploy Overlord RAT on macOS](https://gbhackers.com/fake-zoom-installer-uses-net-downloader/)
- [Fake Zoom Installer Delivers Overlord RAT on macOS](https://www.jamf.com/blog/fake-zoom-installer-delivers-overlord-rat-macos/)
- [Fake Zoom Installer Delivers Overlord RAT to macOS and Windows Systems](https://cyberpress.org/fake-zoom-installer-delivers-overlord-rat/)
- [Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency](https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal)
- [macOS FlexibleFerret | Further Variants of DPRK Malware Family Unearthed](https://www.sentinelone.com/blog/macos-flexibleferret-further-variants-of-dprk-malware-family-unearthed/)
- [Overlord Malware Profile & 7d C2 Tracker](https://www.derp.ca/overlord/)
- [Overlord RAT - Open Source C2 Framework (GitHub)](https://github.com/vxaboveground/Overlord)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1950
